CVE-2018-12420 describes a critical vulnerability in IceHrm versions prior to 23.0.1.OS, where the system insecurely handles hashed passwords within requests. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating that it can be exploited remotely with low complexity, potentially leading to unauthorized disclosure of sensitive information. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, organizations using affected IceHrm versions should prioritize patching to mitigate the risk of data compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.0.1.osCPE matchmatch criteria | cpe:2.3:a:icehrm:icehrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.