HRForecast Suite SmartLibrary SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the smartLibrary component of HRForecast Suite version 0.4.3. The issue resides in the valueKey parameter of the api/smartlibrary/v2/en/dictionaries/options/lookup endpoint. This vulnerability allows authenticated users to execute arbitrary SQL queries by sending crafted payloads through the valueKey parameter.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the application's database.

Added: Aug 19, 2025, 5:25 PM
Updated: Aug 19, 2025, 5:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.