6.5 CVE-2025-51506

 

In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
https://nvd.nist.gov/vuln/detail/CVE-2025-51506

Categories

CWE-89

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:talentneuron:hrforecast_suite:0.4.3:*:*:*:*:*:*:*


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry