Skip to main content

Vendor archive

humanica CVEs

Beta · best-effort

4 CVEs tagged to vendor humanica1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2019-16106

Published Sep 10, 2019

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15130

Published Aug 18, 2019

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a craf…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15129

Published Aug 18, 2019

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by spec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14932

Published Aug 12, 2019

The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1