Vulmon Recent Vulnerabilities Trends Blog About Contact

hrsale vulnerabilities and exploits

(subscribe to this query)

NA
CVE-2020-27993
Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files....
NA
CVE-2020-29053
HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter....
355
VMScore
CVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user....
655
VMScore
CVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query....
655
VMScore
CVE-2018-10260
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user....
655
VMScore
CVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution....
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
overflowCVE-2021-24122firewallCVE-2021-21010CVE-2021-0219CVE-2020-14101HTML injectionCVE-2020-6207envira galleryCVE-2021-0220enviragallery
Home Recent Vulnerabilities Trends Blog About Contact