{"id":"CVE-2026-15721","published":"2026-08-04T10:19:32.667","lastModified":"2026-08-04T14:16:30.620","description":"Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection.\n\nThis issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-312"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0737","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources versions before 26.1, allowing attackers to access sensitive data through unencrypted storage and execute malicious SQL commands.","exploitability":"Exploitation requires access to the affected application's database or network traffic interception; preconditions include the presence of sensitive information stored in cleartext.","blast_radius":"If exploited, this vulnerability could lead to unauthorized data exposure, system compromise, and potential loss of confidentiality and integrity of sensitive HR data.","remediation":"Update HUMANIST Digital Human Resources to version 26.1 or later to mitigate the SQL Injection risk and ensure secure storage of sensitive information.","tags":["sql-injection","data-exposure","patch-available"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:41:26.224Z"}}