Impact
The flaw is a stored cross‑site scripting vulnerability in Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources. When a malicious script is submitted through an allowed input field, it is persistently stored and later rendered as part of a web page for any user who views that content. The defect is classified as CWE‑79 and carries a CVSS score of 5.4, indicating a medium‑severity risk.
Affected Systems
Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources, versions prior to 26.1, including 26.0, are affected. Any installation of the product that has not been upgraded to the 26.1 release or newer remains vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attacker would need to submit malicious input through an input field that is later rendered into a web page. The likely attack vector is the web interface, but this is not stated directly in the CVE data. The exploit requires another user to view the resulting content after the payload is stored. The CVSS score of 5.4 indicates a medium severity, and the EPSS score is <1% with no listing in KEV, suggesting limited public exploitation.
OpenCVE Enrichment