CVE-2025-48780

Severity CVSS v4.0:
CRITICAL
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
06/06/2025
Last modified:
04/02/2026

Description

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:* 7.3.2025.0408 (including)


References to Advisories, Solutions, and Tools