Input Validation Flaw in OrangeHRM Allows Command Execution by Authenticated Users
CVE-2019-12839

8.8HIGH

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
15 June 2019

What is CVE-2019-12839?

In versions of OrangeHRM prior to 4.3.1, an input validation error exists in the admin/listMailConfiguration function, specifically concerning the txtSendmailPath parameter. This flaw permits authenticated attackers to execute arbitrary commands on the server. Proper validation mechanisms are essential to prevent the exploitation of this vulnerability, hence safeguarding the application and its data.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.