← Retour à la recherche de CVE

CVE-2026-38568

HireFlow

Description

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner or has an authorized role. Any authenticated user can access any other user-s candidate profiles and interview notes by iterating the integer ID in the URL path, constituting a horizontal privilege escalation and full data breach of all records in the system.

CVSS 8.1EPSS 0.231%Risque 0.83
Voir la source
Publication
2026-05-11 18:16:32
Versions concernées
<1.2.1
Type
Installed app
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N