Orangehrm

Orangehrm

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 29.11.2025 03:08:00
  • Zuletzt bearbeitet 03.12.2025 16:30:13

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, w...

  • EPSS 0.03%
  • Veröffentlicht 29.11.2025 03:06:56
  • Zuletzt bearbeitet 03.12.2025 16:46:12

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users re...

  • EPSS 0.06%
  • Veröffentlicht 29.11.2025 03:06:25
  • Zuletzt bearbeitet 03.12.2025 16:47:32

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain va...

  • EPSS 0.05%
  • Veröffentlicht 29.11.2025 03:05:46
  • Zuletzt bearbeitet 03.12.2025 16:51:00

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was orig...

  • EPSS 0.11%
  • Veröffentlicht 29.11.2025 03:04:42
  • Zuletzt bearbeitet 03.12.2025 16:55:22

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail configuration and delivery workflow that allows user-controlled values to flow directly in...

  • EPSS 0.1%
  • Veröffentlicht 21.05.2025 00:00:00
  • Zuletzt bearbeitet 13.10.2025 20:15:33

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential s...

Exploit
  • EPSS 77.1%
  • Veröffentlicht 27.05.2024 23:15:13
  • Zuletzt bearbeitet 23.06.2025 18:09:47

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 20.05.2022 02:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:17

A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.04.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:55:10

OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.04.2022 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:55:09

OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.