CVE-2026-15804 Details
Description
The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.
A SQL injection vulnerability has been identified in the HCM application developed by MetaGuru. This issue affects authenticated remote attackers, who can inject SQL commands through specific parameters. The vulnerability impacts the confidentiality, integrity, and availability of database information. It is present in HCM version 7 prior to 7.5.3 and in HCM version 8 prior to 8.1.7.1.
Users are advised to update HCM version 7 to 7.5.3 or later, and to update HCM version 8 to 8.1.7.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-11036-986ec-2.html | [email protected] | AdvisoryRemedy |
| https://www.twcert.org.tw/tw/cp-132-11035-5c640-1.html | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MetaGuru HCM | >= 7, < 7.5.3 >= 8, < 8.1.7.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion