Executive brief
TalentSys Inka.Net, a human resources and workforce management platform, contains a critical security flaw that allows unauthorized users to upload malicious files. By exploiting this vulnerability, an attacker can remotely execute commands on the server, potentially leading to a total takeover of the system. This could result in the theft of sensitive employee data, disruption of business operations, and complete loss of system integrity.
Technical details
A critical vulnerability (CWE-434) exists in TalentSys Inka.Net versions prior to 6.7.1 due to insufficient validation of uploaded files. An unauthenticated remote attacker can upload a file with a dangerous extension or content, which the server then processes or executes. This leads to command injection, granting the attacker the ability to execute arbitrary code with the privileges of the web service. The vulnerability has a CVSS 3.1 score of 10.0, reflecting its low complexity and lack of required authentication. Users are advised to upgrade to version 6.7.1 or later to mitigate this risk.
Affected products
- TalentSys Consulting Information Technology Industry Inc. Inka.Net before 6.7.1
Timeline
- 2025-09-23: disclosed
- 2025-09-23: advisory