Soar Cloud HRD Human Resource Management System - Unrestricted Upload of File with Dangerous Type
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.9epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
Affected products
Soar Cloud System CO., LTD. · HRD Human Resource Management SystemReferences
https://zuso.ai/advisory/za-2025-07