Executive brief
CB Project Ltd. Co. CVLand, a platform used for managing resumes and recruitment data, contains a critical security flaw that allows users to bypass authorization. By manipulating specific parameters, an attacker can gain unauthorized access to data or perform actions they are not permitted to do. This could lead to the exposure of sensitive personal information or the unauthorized modification of records. As of the latest report, the vendor has not responded to disclosure attempts, and no patch is currently available.
Technical details
An authorization bypass vulnerability (CWE-639) exists in CB Project Ltd. Co. CVLand versions 2.1.0 through 20251103. The flaw stems from the application relying on user-controlled keys to perform authorization checks, which allows for parameter injection. A remote attacker with low-level privileges can exploit this by manipulating request parameters to access or modify resources belonging to other users. The vulnerability has a CVSS score of 9.9 due to its potential for high impact on confidentiality and integrity across security scopes. No official patch has been released as the vendor did not respond to the disclosure.
Affected products
- CB Project Ltd. Co. CVLand 2.1.0 through 20251103
Timeline
- 2025-11-03: disclosed: Vulnerability disclosed by TR-CERT (USOM)
- 2025-11-03: advisory: CVE-2025-0987 published