Vulnerabilities (CVE)

Filtered by vendor Orangehrm Subscribe
Total 31 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-44040 1 Orangehrm 1 Orangehrm 2025-10-13 N/A 7.2 HIGH
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed by the Supplier because an adversary has no way to place the specific MD5 value into the credential store (unless they already have full privileges) and because the specific MD5 value would not realistically be present otherwise.
CVE-2024-36428 1 Orangehrm 1 Orangehrm 2025-06-23 N/A 8.1 HIGH
OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
CVE-2022-28985 1 Orangehrm 1 Orangehrm 2024-11-21 3.5 LOW 6.3 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2022-27110 1 Orangehrm 1 Orangehrm 2024-11-21 4.9 MEDIUM 5.4 MEDIUM
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
CVE-2022-27109 1 Orangehrm 1 Orangehrm 2024-11-21 4.9 MEDIUM 5.4 MEDIUM
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
CVE-2022-27108 1 Orangehrm 1 Orangehrm 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
CVE-2022-27107 1 Orangehrm 1 Orangehrm 2024-11-21 3.5 LOW 5.4 MEDIUM
OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo[linkAddress]" parameter
CVE-2021-28399 1 Orangehrm 1 Orangehrm 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
CVE-2020-29437 1 Orangehrm 1 Orangehrm 2024-11-21 5.5 MEDIUM 8.1 HIGH
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
CVE-2019-12839 1 Orangehrm 1 Orangehrm 2024-11-21 6.5 MEDIUM 8.8 HIGH
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.
CVE-2013-1353 1 Orangehrm 1 Orangehrm 2024-11-21 3.5 LOW 5.4 MEDIUM
Orange HRM 2.7.1 allows XSS via the vacancy name.