CVE-2025-51989

7.0

Evolution Consulting Kft · HRmaster

An HTML injection vulnerability in the HRmaster module allows unauthenticated attackers to inject malicious HTML tags into the firstname field, facilitating phishing attacks via email.

Executive summary

An unauthenticated HTML injection vulnerability in the Evolution Consulting Kft HRmaster module enables attackers to conduct phishing campaigns against external email addresses.

Vulnerability

This vulnerability involves improper neutralization of user-supplied input within the keresztnév (firstname) field of the registration interface. An unauthenticated attacker can inject arbitrary HTML tags that are subsequently rendered in emails sent by the system.

Business impact

The ability to inject HTML into system-generated emails poses a significant risk of sophisticated phishing attacks, which can lead to credential theft, malware distribution, or loss of organizational trust. With a CVSS score of 7.0, this high-severity flaw requires immediate attention to prevent malicious actors from leveraging the company's own communication channels to deceive users.

Remediation

Immediate Action: Contact the vendor, Evolution Consulting Kft, to confirm the availability of a security patch or configuration update for HRmaster module version 235.

Proactive Monitoring: Review outgoing email logs generated by the HRmaster registration module for unusual HTML syntax or suspicious content patterns.

Compensating Controls: Implement email security solutions that perform deep inspection of outbound links and HTML content to identify and block phishing attempts originating from the application.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the research documentation provided in the CVE references.

Analyst recommendation

Given the potential for successful phishing and the availability of a public proof-of-concept, organizations using HRmaster version 235 must prioritize the mitigation of this flaw. If a vendor-supplied patch is not currently available, ensure that strict input validation is enforced at the application level or limit access to the registration interface until a permanent fix is deployed.

Sources