In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-19T00:00:00.000Z
Updated: 2025-08-19T20:00:09.130Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51506

Updated: 2025-08-19T20:00:03.522Z

Status : Awaiting Analysis
Published: 2025-08-19T17:15:40.450
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-51506

No data.