Showing 1 vulnerability on this page for HRSALE

Signals CISA KEV Ransomware Nuclei
HRSALE vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CWE-352Feb 5, 2026
CVSS5.1v4.0EPSS0.156%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX