CVE-2025-29033 | BambooHR 25.0210.170831-83b08dd HTTP GET Parameter /saml/index.php privilege escalation
A vulnerability classified as critical has been found in BambooHR 25.0210.170831-83b08dd. This affects an unknown part of the file /saml/index.php of the component HTTP GET Parameter Handler. The manipulation of the argument r leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2025-29033. It is possible to initiate the attack remotely. There is no exploit available.