OrangeHRM
cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*
- >= 5.0, <= 5.8
A vulnerability in OrangeHRM Open Source versions 5.0 through 5.8 allows authenticated users to bypass access controls for disabled modules. This is achieved through URL-encoded request paths, enabling access to functionalities of modules that an administrator has disabled. The issue has been fixed in version 5.8.1.
Exploiting this vulnerability could lead to unauthorized access to module functionalities that are meant to be disabled, potentially allowing users to manipulate or view information they should not have access to.
Users can upgrade to OrangeHRM Open Source version 5.8.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.