Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026071604073838 | Publication Time | 2026-07-16 16:32:39 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-07-16 16:32:39 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Julu Digital|HCM - SQL Injection |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000010 【Julu Digital|HCM - SQL Injection】(CVE-2026-15804, CVSS: 8.8) The HCM system developed by Julu Digital contains an SQL Injection vulnerability. An authenticated remote attacker may inject SQL commands through specific parameters, affecting the confidentiality, integrity, and availability of database data. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
HCM versions 7 to 7.5.3 (exclusive) HCM versions 8 to 8.1.7.1 (exclusive) |
|||
|
[Recommended Actions] Please update HCM 7 to version 7.5.3 or later Please update HCM 8 to version 8.1.7.1 or later |
|||
|
[Reference] |
|||