Vulnerability Description
A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument eventSubject causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Angeljudesuarez | Human Resource Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/f14g-orz/CVE/issues/8ExploitIssue TrackingThird Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.332942Permissions RequiredVDB Entry
- https://vuldb.com/?id.332942Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.695952Third Party AdvisoryVDB Entry
- https://github.com/f14g-orz/CVE/issues/8ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2025-13420?
CVE-2025-13420 is a vulnerability with a CVSS score of 7.3 (HIGH). A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argument...
How severe is CVE-2025-13420?
CVE-2025-13420 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13420?
Check the references section above for vendor advisories and patch information. Affected products include: Angeljudesuarez Human Resource Management System.