HRSALE Vulnerabilities and Affected Products
Vulnerabilities associated with HRSALE.
Products
Clear product- HRSALE1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37145MEDIUM | HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges. CWE-352Feb 5, 2026 | CVSS5.1v4.0 | EPSS0.156% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |