CPE
An unauthenticated arbitrary file read vulnerability (CVE-2024-58387) in Inspur Haiyue HCM Cloud allows remote attackers to disclose sensitive system files via the /api/model_report/file/download endpoint.