CyberRota Analysis
AI-GeneratedIceHRM versions prior to 36.0.0 are vulnerable due to inadequate validation of employee ownership on multiple REST sub-resource endpoints, enabling authenticated users to access and read sensitive HR records of any colleague. This flaw allows attackers to manipulate employee IDs to retrieve confidential information related to skills, education, certifications, and attendance. Organizations using affected versions should prioritize patching to protect employee privacy and maintain compliance with data protection regulations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance, and status endpoints to access sensitive personnel data.