Impact
The MetaGuru HCM application contains a high‑severity SQL Injection flaw. Authenticated remote attackers can supply crafted input through certain parameters to inject arbitrary SQL commands. Successful exploitation would allow the attacker to read, modify, or delete data in the database, thereby breaching confidentiality, integrity, and potentially disrupting service availability. This weakness is identified as CWE‑89.
Affected Systems
The vulnerability is present in MetaGuru HCM versions that do not incorporate the vendor’s latest fixes. Specifically, any instance of HCM 7 prior to 7.5.3 and any instance of HCM 8 prior to 8.1.7.1 is affected. TheseGuru HCM platform.
Risk and Exploitability
The CVSS score of 8.7 indicates a high risk to affected systems. The EPSS score is <1%, indicating a very low but nonzero exploitation probability; the exact likelihood cannot be precisely quantified, but the low EPSS together with the high CVSS still raises concern. The attack vector be an authenticated remote attacker who can submit requests to vulnerable endpoints; therefore, compromising user credentials or successfully leveraging an existing account would provide the necessary access to execute the injection. The vulnerability is not listed in CISA’s KEV catalog, but the potential for data breach warrants prompt action.
OpenCVE Enrichment