CVE-2019-11032: Hr-Technologies Easytorecruit

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross Site Scripting (XSS) injection in multiple locations.

Affected products

Published 2019-04-24. Last modified 2026-06-17.