CVE-2018-10256: Hrsale Project Hrsale

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

Affected products

Published 2018-05-01. Last modified 2026-06-17.