First published: Fri Mar 21 2025(Updated: )
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Human Resource Management System | ||
code-projects Human Resource Management | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2589 is classified as a critical vulnerability.
CVE-2025-2589 affects the code-projects Human Resource Management System version 1.0.1.
CVE-2025-2589 exploits improper authorization through manipulation of the user_cookie argument.
To fix CVE-2025-2589, update the Human Resource Management System to a patched version that addresses this vulnerability.
CVE-2025-2589 is associated with the file \handler\Account.go.