Vendor
The vhr application contains an authorization bypass vulnerability in the PUT /hr/info endpoint that allows authenticated users to modify arbitrary HR profiles, including administrator accounts.