Executive brief
lenve vhr is a Human Resources management system used by organizations to manage employee information. The password change functionality contains an authorization bypass flaw that allows any authenticated user to change another employee's password if they know the victim's old password, potentially leading to account takeover. This risk is heightened when default or weak passwords are in use across the organization.
Technical details
The vulnerability is an improper authorization (CWE-285) flaw in the HrInfoController.updatePass() function of the /hr/pass endpoint. The root cause is that the hrid (Human Resource ID) parameter submitted by the client is not validated against the authenticated user's actual identity—there is no check to ensure hrid matches the current user's ID. An authenticated attacker can change any user's password by crafting a PUT request with a target hrid, the victim's old password, and a new password. The vulnerability requires network access and valid authentication credentials, but can be exploited by any logged-in user to compromise any other user account.
Affected products
- lenve vhr 1.0-SNAPSHOT
Timeline
- 2026-09-13: disclosed
- exploited: Exploit has been released to the public