CodeAstro human resource management system是CodeAstro公司的企业人力资源管理软件。 CodeAstro Human Resource Management System 1.0版本存在安全漏洞,该漏洞源于View Endpoint组件中GetFileInfo函数对参数ID的错误操作,可能导致SQL注入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CodeAstro | Human Resource Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CodeAstro | Human Resource Management System | 1.0 |
cpe:2.3:a:codeastro:human_resource_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13525 | 6.3 MEDIUM | CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php e |
| CVE-2026-13549 | 5.4 MEDIUM | CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorizatio |
| CVE-2026-13537 | 4.3 MEDIUM | CodeAstro Human Resource Management System cross-site request forgery |
| CVE-2026-13558 | 3.5 LOW | CodeAstro Complaint Management System Report addreport cross site scripting |
No comments yet