Vulnerabilities > CVE-2025-2589 - Missing Authorization vulnerability in Code-Projects Human Resource Management 1.0.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been disclosed to the public and may be used.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |