OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58387

HIGH · CVSS 7.5 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Inspur Haiyue HCM Cloud is vulnerable to an arbitrary file read flaw in the /api/model_report/file/download endpoint, allowing unauthenticated remote attackers to exploit unvalidated path parameters to traverse the filesystem. This vulnerability can lead to the exposure of sensitive files, including system configuration and application database files. Organizations using this cloud service should prioritize remediation to prevent potential data breaches and unauthorized access to critical information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58387
Severity
HIGH
CVSS
7.5
EPSS
0.55%

Original NVD Description

Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .