Junglewise Threat Intelligence

CVE-2026-15478: Gamonoid IceHRM SQL injection in UserReport endpoint

CVE-2026-15478 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Executive brief

IceHRM, an open-source Human Resource Management system, contains a security vulnerability in its reporting module. An authenticated user, such as a standard employee, can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive company information, including employee records, salaries, and login credentials.

Technical details

A SQL injection vulnerability exists in IceHRM versions up to 35.0.1 within the UserReport endpoint. The flaw is located in core/src/Reports/User/Reports/EmployeeAttendanceReport.php (and several other report files) where the 'employeeList' argument is JSON-decoded and passed directly into a SQL IN clause via the implode() function without parameterization or type casting. An authenticated attacker with 'Employee' level privileges can provide a malicious JSON array to execute arbitrary SQL commands. This can be exploited via time-based or error-based blind injection to exfiltrate sensitive data from the database. As of the advisory date, the project has been informed but a formal patch has not been confirmed.

Affected products

  • Gamonoid IceHRM up to 35.0.1

Timeline

  • 2026-06-14: disclosed: Issue reported to vendor via GitHub issue #376
  • 2026-07-12: advisory: CVE published by VulDB/NVD

References