An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-029.txt