Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
icehrm vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-6282
IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payloa...
Icehrm Icehrm 23.0.0.os
5.4
CVSSv3
CVE-2021-38822
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.
Icehrm Icehrm 30.0.0.os
9.8
CVSSv3
CVE-2021-38823
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
Icehrm Icehrm 30.0.0.os
6.5
CVSSv3
CVE-2022-26588
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows malicious users to delete arbitrary users or achieve account takeover via the app/service.php URI.
Icehrm Icehrm 31.0.0.os
6.1
CVSSv3
CVE-2022-25014
Ice Hrm 30.0.0.OS exists to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows malicious users to compromise session credentials via user interaction with a crafted link.
Icehrm Icehrm 30.0.0.os
NA
CVE-2022-265881
ICEHRM version 31.0.0.0S cross site request forgery exploit that demonstrates account deletion. This finding varies from the original finding of cross site request forgery in the same software from the same researcher.
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-34377
CVE-2024-20859
CVE-2023-49606
inject
arbitrary
CVE-2024-33788
CVE-2024-30973
IDOR
CVE-2024-33907
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2