CVE-2025-66225 is a critical authentication bypass vulnerability affecting OrangeHRM versions 5.0 through 5.7. It allows an attacker to reset the password of any user, including privileged accounts, by manipulating the username parameter during the final step of the password reset process, leading to full account takeover. With a CVSS score of 8.8 (High), this flaw is easily exploitable over the network with low privileges and no user interaction. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 90/100 indicates significant potential impact. Organizations using affected OrangeHRM versions should upgrade to version 5.8 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.8CPE matchmatch criteria | cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.