CVE-2018-10257: Hrsale Project Hrsale
High severity, CVSS 8.8. EPSS: 4.2% chance of exploitation in the next 30 days.
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
Affected products
- Hrsale Project Hrsale: version 1.0.2 only
Published 2018-05-01. Last modified 2026-06-17.