Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-37145 | 1 Hrsale | 1 Hrsale | 2026-02-06 | 4.3 Medium |
| HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges. | ||||
| CVE-2020-29053 | 1 Hrsale | 1 Hrsale | 2024-11-21 | 6.1 Medium |
| HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter. | ||||
| CVE-2020-27993 | 1 Hrsale | 1 Hrsale | 2024-11-21 | 5.3 Medium |
| Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files. | ||||
Page 1 of 1.