Executive brief
Evolution Consulting Kft. HRmaster, a human resources management platform, contains a security flaw in its registration interface. An attacker can input malicious code into the first name field during registration or job application. This code is then automatically included in emails sent by the system, allowing attackers to send deceptive phishing messages to unsuspecting users from a legitimate corporate email address.
Technical details
An HTML injection vulnerability exists in the registration interface of Evolution Consulting Kft. HRmaster module v235. The root cause is improper neutralization of input in the 'keresztnév' (firstname) field. An unauthenticated remote attacker can inject arbitrary HTML tags into this field. When the system generates automated confirmation emails for registration or job applications, the injected HTML is rendered in the recipient's email client. This can be leveraged to perform phishing attacks against any email address not previously registered in the system. The vulnerability is tracked as CWE-80.
Affected products
- Evolution Consulting Kft. HRmaster v235
Timeline
- 2025-05: disclosed: Discovered by Szilagyi Apor
- 2025-08-21: advisory: NVD publication date