HRSALE Cross-Site Request Forgery Vulnerability Allowing Unauthorized Admin User Creation

Vulnerability

A cross-site request forgery (CSRF) vulnerability exists in HRSALE version 1.1.8. This vulnerability allows attackers to add unauthorized administrative users through the employee registration form. By crafting a malicious HTML page with hidden form fields, attackers can deceive authenticated administrators into creating new user accounts with elevated privileges.

Impact

Exploitation of this vulnerability allows for the unauthorized addition of administrative users, potentially leading to misuse of elevated privileges.

Reproduction

To exploit this vulnerability, a CSRF attack can be performed by sending an authenticated administrator a crafted HTML page that includes a form. This form should be set to submit to the employee registration endpoint with the necessary fields populated, including the 'csrf_hrsale' token to bypass CSRF protection. Once the administrator submits the form, the new user account with admin privileges will be created.

Added: Feb 5, 2026, 5:34 PM
Updated: Feb 5, 2026, 9:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.6
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.