
CVE-2020-37145 HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form… https://www.cve.org/CVERecord?id=CVE-2020-37145
Post summary
CVE‑2020‑37145 is a disclosed CSRF vulnerability in HRSALE 1.1.8 that lets attackers create unauthorized admin accounts through the employee registration form; no PoC, exploit code, or patch information is provided.
