OrangeHRM
cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*
- >= 5.0, <= 5.8
An authorization vulnerability has been identified in OrangeHRM Open Source versions 5.0 through 5.8. The issue arises in the job specification and vacancy attachment download handlers, where authorization checks are omitted. This flaw allows authenticated low-privilege users to access attachments by directly referencing attachment identifiers.
Exploitation of this vulnerability could lead to unauthorized access to job specification and vacancy attachments, allowing low-privilege users to read these files without proper authorization.
Users can upgrade to OrangeHRM Open Source version 5.8.1 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.