CVE-2024-5995: Scshr Hr Portal
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
Affected products
- Scshr Hr Portal: before 7.3.2024.0409 (fixed in 7.3.2024.0409)
- Soar Cloud Hr Portal
Published 2024-06-14. Last modified 2026-06-17.