Skip to main content

Restricted fields manipulation


From the self-management functionality for the registration of an employee, it is possible to change the information of other employees from other companies. An attacker can initiate a request to confirm the registration of an employee and change the DNI to different values so that it replaces the existing data. In this way the information sent will be stored in the company, updating all the information of the targeted employees such as names, e-mail addresses, dates of birth, addresses, telephone numbers, among others.


Modify or replace the information of other employees independently of the company.


Verify that the user who is trying to modify the information has the necessary permissions to access.


External attacker with access to employees information.

Expected Remediation Time

⌚ minutes.


Default score using CVSS 3.1. It may change depending on the context of the src.


  • Attack vector: N
  • Attack complexity: L
  • Privileges required: H
  • User interaction: N
  • Scope: U
  • Confidentiality: N
  • Integrity: H
  • Availability: N


  • Exploit code madurity: X
  • Remediation level: X
  • Report confidence: X


  • Vector string: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:X/RL:X/RC:X
  • Score:
    • Base: 4.9
    • Temporal: 4.9
  • Severity:
    • Base: Medium
    • Temporal: Medium



free trial

Search for vulnerabilities in your apps for free with our automated security testing! Start your 21-day free trial and discover the benefits of our Continuous Hacking Machine Plan. If you prefer a full service that includes the expertise of our ethical hackers, don't hesitate to contact us for our Continuous Hacking Squad Plan.