CVE-2025-63294

W

orkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users.

Configurations

Configuration 1 (hide)

cpe:2.3:a:workdo:hrm_saas:8.1:*:*:*:*:*:*:*

History

04 Feb 2026, 20:15

Type Values Removed Values Added
References () https://codecanyon.net/item/hrm-saas-hr-and-payroll-tool/25982934 - () https://codecanyon.net/item/hrm-saas-hr-and-payroll-tool/25982934 - Product
References () https://medium.com/@barrattjack89/cve-2025-63294-insecure-permissions-in-workdo-hrm-saas-hr-and-payroll-8-1-d6bb03c21177 - () https://medium.com/@barrattjack89/cve-2025-63294-insecure-permissions-in-workdo-hrm-saas-hr-and-payroll-8-1-d6bb03c21177 - Exploit, Third Party Advisory
References () https://workdo.io/hrm-saas-human-resource-management-software/ - () https://workdo.io/hrm-saas-human-resource-management-software/ - Product
First Time Workdo
Workdo hrm Saas
CPE cpe:2.3:a:workdo:hrm_saas:8.1:*:*:*:*:*:*:*

04 Nov 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-04 16:16

Updated : 2026-02-04 20:15


NVD link : CVE-2025-63294

Mitre link : CVE-2025-63294

CVE.ORG link : CVE-2025-63294


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization