CVE-2019-11032: Hr-Technologies Easytorecruit
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross Site Scripting (XSS) injection in multiple locations.
Affected products
- Hr-Technologies Easytorecruit: before 2.11 (fixed in 2.11)
Published 2019-04-24. Last modified 2026-06-17.