← back
CVE-2025-48782criticalCWE-434

Soar Cloud HRD Human Resource Management System - Unrestricted Upload of File with Dangerous Type

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.9epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H