Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
Vulnerability Description
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Hrsale 跨站请求伪造漏洞
Vulnerability Description
Hrsale是Hrsale团队的一款PHP编写的人力资源管理系统。 Hrsale 1.1.8版本存在跨站请求伪造漏洞,该漏洞源于存在跨站请求伪造,可能导致添加未授权管理用户。
CVSS Information
N/A
Vulnerability Type
N/A