Description
In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
Published: 2025-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25191 In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
History

Tue, 07 Oct 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Talentneuron
Talentneuron hrforecast Suite
CPEs cpe:2.3:a:talentneuron:hrforecast_suite:0.4.3:*:*:*:*:*:*:*
Vendors & Products Talentneuron
Talentneuron hrforecast Suite

Tue, 19 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 17:00:00 +0000

Type Values Removed Values Added
Description In the smartLibrary component of the HRForecast Suite 0.4.3, a SQL injection vulnerability was discovered in the valueKey parameter. This flaw enables any authenticated user to execute arbitrary SQL queries, via crafted payloads to valueKey to the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint.
References

Subscriptions

Talentneuron Hrforecast Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-19T20:00:09.130Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51506

cve-icon Vulnrichment

Updated: 2025-08-19T20:00:03.522Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-19T17:15:40.450

Modified: 2025-10-07T21:08:37.287

Link: CVE-2025-51506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses