PT-2026-57523 · Ice Hrm · Ice Hrm
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IceHRM versions prior to 35.0.2
Description
A remote SQL injection flaw exists in the UserReport component within the file
core/src/Reports/User/Reports/EmployeeAttendanceReport.php. The issue occurs when the employeeList argument is manipulated, allowing an attacker to execute unauthorized SQL commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
employeeList argument in the affected component to minimize the risk of exploitation.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ice Hrm