CVE-2025-48780: Scshr Hr Portal

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

Affected products

  • Scshr Hr Portal: up to and including 7.3.2025.0408

Published 2025-06-06. Last modified 2026-06-17.