Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22994 | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint. |
Mon, 04 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oretnom23
Oretnom23 human Resource Management System |
|
| CPEs | cpe:2.3:a:oretnom23:human_resource_management_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oretnom23
Oretnom23 human Resource Management System |
|
| Metrics |
cvssV3_1
|
Tue, 29 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint. | |
| Title | SQL injection vulnerability in Human Resource Management System | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-29T13:40:18.561Z
Reserved: 2025-04-16T08:38:16.029Z
Link: CVE-2025-40682
Updated: 2025-07-29T13:40:14.287Z
Status : Analyzed
Published: 2025-07-29T13:15:26.107
Modified: 2025-08-04T20:59:01.080
Link: CVE-2025-40682
No data.
OpenCVE Enrichment
No data.
EUVD