Home

Description

In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.

PUBLISHED Reserved 2025-06-16 | Published 2025-08-19 | Updated 2025-08-19 | Assigner mitre

References

hrforecast.com/

hrforecast.com/smartlibrary-job-architecture/

github.com/MVRC-ITSEC/CVEs/blob/main/CVE-2025-51506

cve.org (CVE-2025-51506)

nvd.nist.gov (CVE-2025-51506)

Download JSON