vendor:
HRSALE The Ultimate HRM
by:
8bitsec
8.8
CVSS
HIGH
CSV Injection
79
CWE
Product Name: HRSALE The Ultimate HRM
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: YES
Related CWE: CVE-2018-10257
CPE: 2.3:a:codecanyon:hrsale_the_ultimate_hrm:1.0.2:*:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux 2.0, Mac OS 10.13
2018
HRSALE The Ultimate HRM 1.0.2 – CSV Injection
A user is able to inject a command that will be included in the exported CSV file. To exploit this vulnerability, a user must login with employee user credentials, browse to My Profile and add =cmd|'/C calc'!A1 into the First Name field. Then, the user must log in with admin's credentials, browse to Core HR > Employees Last Login, click on the CSV button to download and open the exported CSV file. The calculator will be opened.
Mitigation:
Upgrade to version 1.0.3 or later.