SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the Uname (UserName) parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 79.9%