CVE-2018-10257: Hrsale Project Hrsale

High severity, CVSS 8.8. EPSS: 4.2% chance of exploitation in the next 30 days.

A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Affected products

Published 2018-05-01. Last modified 2026-06-17.