Impact
The vulnerability permits attackers to inject malicious SQL through the query console, enabling arbitrary SQL execution and direct access to database contents. Because the system stores sensitive information in cleartext, exploitation can result in the disclosure of confidential employee and organizational data. This weakness is identified as CWE‑312, reflecting improper handling of sensitive data during transmission or storage.
Affected Systems
Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources product, versions 26.0 up to but not including 26.1, are affected. The CVE specifically identifies version 26.0 as vulnerable; earlier releases are not explicitly confirmed as impacted.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as Critical, indicating a high potential for widespread data loss. The EPSS score is reported as < 1 %, suggesting a low but non‑zero probability of exploitation. Because the flaw involves remote execution of arbitrary SQL via the query console, an attacker with network access to the application could potentially extract sensitive data stored in cleartext. The vulnerability is not listed in the CISA KEV catalog, supporting the lack of public exploitation reports but not eliminating risk. The combination of a severe CVSS score, a possibly accessible query console, and cleartext storage makes the flaw highly actionable for attackers who can reach the console.
OpenCVE Enrichment