Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icehrm icehrm vulnerabilities and exploits
(subscribe to this query)
445
VMScore
CVE-2018-12420
IceHrm prior to 23.0.1.OS has a risky usage of a hashed password in a request.
Icehrm Icehrm
383
VMScore
CVE-2022-25013
Ice Hrm 30.0.0.OS exists to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.
Icehrm Icehrm 30.0.0.os
383
VMScore
CVE-2022-25014
Ice Hrm 30.0.0.OS exists to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows malicious users to compromise session credentials via user interaction with a crafted link.
Icehrm Icehrm 30.0.0.os
312
VMScore
CVE-2022-25015
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows malicious users to steal cookies via a crafted payload inserted into the First Name field.
Icehrm Icehrm 30.0.0.os
605
VMScore
CVE-2021-34244
A cross site request forgery (CSRF) vulnerability exists in Ice Hrm 29.0.0.OS which allows malicious users to create new admin accounts or change users' passwords.
Icehrm Icehrm 29.0.0.os
312
VMScore
CVE-2021-34243
A stored cross site scripting (XSS) vulnerability exists in Ice Hrm 29.0.0.OS which allows malicious users to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of the...
Icehrm Icehrm 29.0.0.os
383
VMScore
CVE-2021-35045
Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows malicious users to execute arbitrary code via the parameters to the /app/ endpoint.
Icehrm Icehrm 29.0.0.os
312
VMScore
CVE-2021-38822
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.
Icehrm Icehrm 30.0.0.os
668
VMScore
CVE-2021-38823
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
Icehrm Icehrm 30.0.0.os
NA
CVE-2023-6282
IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payloa...
Icehrm Icehrm 23.0.0.os
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »