Executive brief
Tiobon Employee Self-Service System is a platform used by organizations to allow employees to manage their own HR and administrative tasks. A security flaw in the system's blog search feature allows an attacker to interfere with the underlying database. This could lead to unauthorized access to sensitive employee information or disruption of the service. An exploit for this vulnerability is publicly available, increasing the risk of an attack.
Technical details
A SQL injection vulnerability exists in the Tiobon Employee Self-Service System up to version 7.2. The flaw is located within the 'Keyword' argument of the /Blog/BlogSearch.aspx file, which is part of the Login Endpoint component. An attacker with low-level privileges can exploit this by sending specially crafted network requests to the server. Successful exploitation allows for the execution of arbitrary SQL commands, potentially leading to data exfiltration or modification. A public exploit has been released, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Tiobon Employee Self-Service System up to 7.2
Timeline
- 2026-06-07: advisory: NVD publication date
- 2026-06-07: disclosed: Public disclosure of the vulnerability and exploit