Vulnerabilities (CVE)

Filtered by vendor Orangehrm Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29437 1 Orangehrm 1 Orangehrm 2021-01-07 5.5 MEDIUM 8.1 HIGH
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
CVE-2019-12839 1 Orangehrm 1 Orangehrm 2020-08-24 6.5 MEDIUM 8.8 HIGH
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.