CVE-2025-48783: Soar Cloud HRD Human Resource Management System - External Control of File Name or Path

8.8 CVSS

Description

An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.

Classification

CVE ID: CVE-2025-48783

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Problem Types

CWE-73 External Control of File Name or Path

Affected Products

Vendor: Soar Cloud System CO., LTD.

Product: HRD Human Resource Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.2% (probability of being exploited)

EPSS Percentile: 42.67% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-48783
https://zuso.ai/advisory/za-2025-08

Timeline