Junglewise Threat Intelligence

CVE-2025-51989: Evolution Consulting Kft. HRmaster HTML injection in registration interface

CVE-2025-51989 · Severity: high · CVSS 7 · Published 2025-08-21

Executive brief

Evolution Consulting Kft. HRmaster, a human resources management platform, contains a security flaw in its registration interface. An attacker can input malicious code into the first name field during registration or job application. This code is then automatically included in emails sent by the system, allowing attackers to send deceptive phishing messages to unsuspecting users from a legitimate corporate email address.

Technical details

An HTML injection vulnerability exists in the registration interface of Evolution Consulting Kft. HRmaster module v235. The root cause is improper neutralization of input in the 'keresztnév' (firstname) field. An unauthenticated remote attacker can inject arbitrary HTML tags into this field. When the system generates automated confirmation emails for registration or job applications, the injected HTML is rendered in the recipient's email client. This can be leveraged to perform phishing attacks against any email address not previously registered in the system. The vulnerability is tracked as CWE-80.

Affected products

  • Evolution Consulting Kft. HRmaster v235

Timeline

  • 2025-05: disclosed: Discovered by Szilagyi Apor
  • 2025-08-21: advisory: NVD publication date

References