CVE-2021-22854 describes a critical SQL injection vulnerability in the HR Portal of Soar Cloud System, specifically affecting the hr_portal_project hr_portal product. This flaw allows unauthenticated remote attackers to inject SQL syntax due to insufficient parameter filtering, leading to the complete exfiltration of all database contents without requiring any privileges. Rated with a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and has a high impact on confidentiality. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the lack of community discussion or media coverage is typical for the vast majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.3.2020.1013CPE matchmatch criteria | cpe:2.3:a:hr_portal_project:hr_portal:7.3.2020.1013:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.