PT-2026-39657 · Hireflow · Hireflow

Hijackedamygdala

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-38569

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HireFlow version 1.2
Description Cross Site Scripting (XSS) occurs in candidate detail.html. The issue is triggered via the 'Resume' or 'Feedback Comment' fields through the endpoints "/candidates/add" and "/feedback/add". XSS is a flaw that allows an attacker to inject malicious scripts into web pages viewed by other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-38569

Affected Products

Hireflow