CVE-2025-5192

A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
References
Link Resource
https://zuso.ai/advisory/za-2025-04 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:*

History

04 Feb 2026, 14:28

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de autenticación faltante para funciones críticas en la aplicación cliente de Soar Cloud HRD Human Resource Management System hasta la versión 7.3.2025.0408 permite a atacantes remotos eludir la autenticación y acceder a las funciones de la aplicación.
References () https://zuso.ai/advisory/za-2025-04 - () https://zuso.ai/advisory/za-2025-04 - Third Party Advisory
First Time Scshr hr Portal
Scshr

06 Jun 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 10:15

Updated : 2026-02-04 14:28


NVD link : CVE-2025-5192

Mitre link : CVE-2025-5192

CVE.ORG link : CVE-2025-5192


JSON object : View

Products Affected

scshr

  • hr_portal
CWE
CWE-306

Missing Authentication for Critical Function