VYPR

Haiyue HCM Cloud

by Inspur

CVEs (1)

  • CVE-2024-58387HigSep 30, 2026
    risk 0.49cvss 7.5epss —

    Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as…