Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-51506

Опубликовано: 19 авг. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:talentneuron:hrforecast_suite:0.4.3:*:*:*:*:*:*:*

EPSS

Процентиль: 7%
0.00026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
github
6 месяцев назад

In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.

EPSS

Процентиль: 7%
0.00026
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89