Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Apor

#39276of 53,635
7Total CVSS
Vulnerabilities · 1
PT-2025-34291
7.0
2025-08-21
Unknown · Hrmaster Module · CVE-2025-51989
Name of the Vulnerable Software and Affected Versions: HRmaster module version 235 Description: An HTML injection flaw exists in the registration interface of the HRmaster module. An attacker can inject HTML tags into the `keresztnév` (firstname) field. This injected HTML is included in emails, potentially enabling phishing attacks against previously unregistered email addresses. Recommendations: Sanitize user input in the `keresztnév` (firstname) field during the registration process to prevent HTML injection.