Executive brief
vhr (微人事) is a human resources management system. A low-privilege user can manipulate employee records to reset admin account credentials and gain administrative access, bypassing normal access controls. This allows unauthorized account takeover and administrative control of the HR system without requiring existing admin credentials.
Technical details
The vulnerability is a mass assignment improper input validation flaw in the HrInfoController.updateHr() endpoint (PUT /hr/info). The endpoint accepts JSON input and binds it directly to the Hr object without validating ownership or filtering sensitive fields; an attacker can specify an arbitrary user ID and set the password field to a self-generated BCrypt hash. The HrMapper.xml updates the password when present, enabling a low-privilege user to reset admin credentials. Attack requires low-privilege user authentication (e.g., libai/123) and network access to the PUT /hr/info endpoint; no further user interaction is needed. An attacker gains vertical privilege escalation to ROLE_admin and complete system control. The vendor has been contacted but provided no response or patch.
Affected products
- lenve vhr 1.0-SNAPSHOT
Timeline
- 2026-09-13: disclosed: Vulnerability publicly disclosed
- 2026-09-13: advisory: CVE-2026-90501 published on NVD