Логотип exploitDog
bind:CVE-2025-44040
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-44040

Количество 3

Количество 3

nvd логотип

CVE-2025-44040

9 месяцев назад

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed by the Supplier because an adversary has no way to place the specific MD5 value into the credential store (unless they already have full privileges) and because the specific MD5 value would not realistically be present otherwise.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2025-44040

9 месяцев назад

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges ...

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-vj38-xwp2-x5gc

9 месяцев назад

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via the UserService.php and the checkFOrOldHash function

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed by the Supplier because an adversary has no way to place the specific MD5 value into the credential store (unless they already have full privileges) and because the specific MD5 value would not realistically be present otherwise.

CVSS3: 7.2
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges ...

CVSS3: 7.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-vj38-xwp2-x5gc

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via the UserService.php and the checkFOrOldHash function

CVSS3: 7.2
0%
Низкий
9 месяцев назад

Уязвимостей на страницу