4.3
CVSSv2

CVE-2011-5258

Published: 12/02/2013 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM prior to 2.6.11.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php; or the (3) PATH_INFO to lib/controllers/centralcontroller.php.

Vulnerable Product Search on Vulmon Subscribe to Product

orangehrm orangehrm 2.6.7

orangehrm orangehrm 2.6.6

orangehrm orangehrm 2.6.0.1

orangehrm orangehrm

orangehrm orangehrm 2.6.5

orangehrm orangehrm 2.6.4

orangehrm orangehrm 2.6.8.1

orangehrm orangehrm 2.6.8

orangehrm orangehrm 2.6.1

orangehrm orangehrm 2.6.0

orangehrm orangehrm 2.6.10

orangehrm orangehrm 2.6.9

orangehrm orangehrm 2.6.3

orangehrm orangehrm 2.6.2

Exploits

source: wwwsecurityfocuscom/bid/50857/info OrangeHRM is prone to an SQL-injection and multiple cross-site scripting vulnerabilities Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underly ...
source: wwwsecurityfocuscom/bid/50857/info OrangeHRM is prone to an SQL-injection and multiple cross-site scripting vulnerabilities Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the under ...