Impact
An authenticated user with the HR User role can craft SQL statements by manipulating filter values in the Salary Payments Based on Payment Mode report. The vulnerability lies in the dynamic construction of the WHERE clause and its direct insertion into a string-formatted SQL query, allowing the attacker to read arbitrary database data. The weakness is a classic SQL Injection flaw; the impact is limited to confidentiality leakage of database content, while integrity and availability are not directly affected by this exploit. The relevant CWE is 89.
Affected Systems
Frappe HRMS versions prior to 16.7.0 are affected. The patch is included in release v16.7.0 of the HRMS package. Any deployments using earlier releases with an HR User role should be updated to this latest version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the vulnerability. The EPSS score of less than 1% means that real-world exploitation opportunities are presently low, and the issue is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated HR User to access the report. Should an attacker succeed, they could retrieve sensitive salary and employee data, potentially breaching confidentiality and violating privacy regulations.
OpenCVE Enrichment