CVE-2026-13537

MEDIUM

CodeAstro Human Resource Management System cross-site request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

References (6)

Core 6
Core References
Vdb Entry vdb-entry
VDB-374545 | CodeAstro Human Resource Management System cross-site request forgery
https://vuldb.com/vuln/374545
Signature, Permissions Required signature permissions-required
VDB-374545 | CTI Indicators (IOB, IOC)
https://vuldb.com/vuln/374545/cti
Third Party Advisory third-party-advisory
CVE-2026-13537 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-13537
Third Party Advisory third-party-advisory
Submit #842084 | CodeAstro Human Resource Management System v1.0 Cross-Site Request Forgery (CSRF)
https://vuldb.com/submit/842084
Product product
https://codeastro.com/

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-862
Status published
Products (1)
CodeAstro/Human Resource Management System 1.0
Published Jun 29, 2026
Tracked Since Jun 29, 2026