CyberRota Analysis
AI-GeneratedInspur Haiyue HCM Cloud is vulnerable to an arbitrary file read flaw in the /api/model_report/file/download endpoint, allowing unauthenticated remote attackers to exploit unvalidated path parameters to traverse the filesystem. This vulnerability can lead to the exposure of sensitive files, including system configuration and application database files. Organizations using this cloud service should prioritize remediation to prevent potential data breaches and unauthorized access to critical information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .