PT-2025-34291 · Unknown · Hrmaster Module

Apor

·

Published

2025-08-21

·

Updated

2025-08-21

·

CVE-2025-51989

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: HRmaster module version 235
Description: An HTML injection flaw exists in the registration interface of the HRmaster module. An attacker can inject HTML tags into the keresztnév (firstname) field. This injected HTML is included in emails, potentially enabling phishing attacks against previously unregistered email addresses.
Recommendations: Sanitize user input in the keresztnév (firstname) field during the registration process to prevent HTML injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-51989

Affected Products

Hrmaster Module