SQL Injection Vulnerability in HJSoft HCM Human Resources Management System
CVE-2025-10197
Key Information:
- Vendor
Hjsoft
- Vendor
- CVE Published:
- 10 September 2025
Badges
What is CVE-2025-10197?
A SQL injection vulnerability has been identified in HJSoft's HCM Human Resources Management System, allowing attackers to manipulate the argument ID in the file /templates/attestation/../../selfservice/lawresource/downlawbase. This flaw could be exploited remotely, posing significant risks as the vendor did not respond to disclosures regarding this vulnerability. Immediate measures should be taken to mitigate the risk of an attack on affected versions.
Affected Version(s)
HCM Human Resources Management System 20250822
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved