First published: Fri Mar 27 2020(Updated: )
Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Ehrd | =8 | |
Sun Ehrd | =9 |
Update to version 10 or latest, or contact Sunnet for fixing patch.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10508 is rated as a high severity vulnerability due to improper file storage leading to potential data exposure.
To mitigate CVE-2020-10508, ensure that system files are securely stored and restrict access to sensitive information.
CVE-2020-10508 is an information disclosure vulnerability caused by improper file handling.
CVE-2020-10508 affects Sunnet eHRD versions 8 and 9.
Yes, CVE-2020-10508 can potentially lead to data breaches by exposing confidential information through accessible URLs.