OrangeHRM versions 5.0 through 5.8 contain an authorization bypass vulnerability that allows authenticated low-privilege users to download job specification and vacancy attachments by directly referencing attachment identifiers. This flaw affects the OrangeHRM Open Source product and is remedied in version 5.8.1. The vulnerability presents a MEDIUM severity risk with a CVSS score of 4.3, exploitable over the network by authenticated users without requiring user interaction. The attack has low complexity and is limited to unauthorized reading of attachment data, posing a confidentiality risk with no impact to system integrity or availability. There is no evidence of active exploitation in the wild, no public exploit code availability, and minimal community attention indicated by the low EPSS score of 0.0003 and inactive status on the KEV catalog. Organizations using affected versions should prioritize patching to 5.8.1, though the exploitation likelihood remains low at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0, < 5.8.1CPE matchmatch criteria | cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.