PT-2025-22434 · Orangehrm · Orangehrm

CVE-2025-44040

·

Publicado

2025-05-21

·

Atualizado

2025-12-27

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OrangeHRM version 5.7
Description The issue allows an attacker to escalate privileges through the UserService.php and the checkFOrOldHash function.
Recommendations For OrangeHRM version 5.7, as a temporary workaround, consider disabling the checkFOrOldHash function until a patch is available. Restrict access to the UserService.php to minimize the risk of exploitation.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-44040

Produtos afetados

Orangehrm