HRForecast Suite SmartLibrary SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in the smartLibrary component of HRForecast Suite version 0.4.3. The issue resides in the valueKey parameter of the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint. This vulnerability allows authenticated users to execute arbitrary SQL queries by sending crafted payloads through the valueKey parameter.
Impact
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the application's database.
Added: Aug 19, 2025, 5:25 PM
Updated: Aug 19, 2025, 5:25 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
6.6remediation
0.0relevance
0.4threat
6.4urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
