Executive brief
HireFlow, an interview management system used by recruiters to track candidates and schedules, contains a critical security flaw. An attacker can bypass the login screen to gain full administrative access or steal the entire database, including sensitive candidate records and user credentials. This allows unauthorized individuals to view private hiring data and take control of the recruitment platform without needing a password.
Technical details
HireFlow v1.2 is vulnerable to SQL injection within the login() and search() functions in app.py. The application fails to parameterize user-supplied input, instead concatenating it directly into SQL queries. An unauthenticated remote attacker can exploit the /login endpoint using a crafted username (e.g., admin'--) to bypass authentication checks. Additionally, the /search endpoint is vulnerable to UNION-based SQL injection via the 'q' parameter, enabling the extraction of sensitive data including user credentials and candidate information. The vulnerability is addressed in version 1.3.
Affected products
- StratonWebDesigners HireFlow 1.2
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory: NVD publication date
- 2026-05-11: patched: Patch available in v1.3