PT-2026-57523 · Ice Hrm · Ice Hrm

·

CVE-2026-15478

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IceHRM versions prior to 35.0.2
Description A remote SQL injection flaw exists in the UserReport component within the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php. The issue occurs when the employeeList argument is manipulated, allowing an attacker to execute unauthorized SQL commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the employeeList argument in the affected component to minimize the risk of exploitation.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15478

Affected Products

Ice Hrm