VYPR

Vhr Advisories

by Arrestx

CVEs (4)

  • CVE-2026-90498HigSep 13, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The exploit is publicly available and might be…

  • CVE-2026-90501MedSep 13, 2026
    risk 0.41cvss 6.3epss

    A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote.…

  • CVE-2026-90500MedSep 13, 2026
    risk 0.41cvss 6.3epss

    A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried…

  • CVE-2026-90499MedSep 13, 2026
    risk 0.35cvss 5.4epss

    A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization. The attack can be executed…