Aller au contenu

Fiche vulnérabilité

CVE-2025-40682 : faille critique oretnom23 human resource management… (CVSS 9.8)

Description

SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • oretnom23 human resource management system

Références

Rechercher une autre vulnérabilité dans la base CVE