关键漏洞信息 漏洞类型: SQL Injection 受影响组件: Parameter: valueKey in 攻击类型: Remote 影响: Information Disclosure (true) 其他影响: Reading and accessing database information and schemas and executing sql queries 攻击向量: Exploiting this vulnerability requires only valid user credentials; no additional authorization for the smartLibrary component is needed. 厂商确认: true 发现者: Marc Mahlke 参考链接: - https://hrforecast.com/ - https://hrforecast.com/smartlibrary-job-architecture/ 产品供应商: HRForecast 受影响的产品版本: smartLibrary v0.4.3 时间线: - 01-APR-2025: Reported to vendor - 04-APR-2025: The vulnerability has been fixed - 01-JUL-2025: End of 90 days Full Disclosure Time - 13-AUG-2025: FULL disclosure