Input Validation Flaw in OrangeHRM Allows Command Execution by Authenticated Users
CVE-2019-12839
8.8HIGH
What is CVE-2019-12839?
In versions of OrangeHRM prior to 4.3.1, an input validation error exists in the admin/listMailConfiguration function, specifically concerning the txtSendmailPath parameter. This flaw permits authenticated attackers to execute arbitrary commands on the server. Proper validation mechanisms are essential to prevent the exploitation of this vulnerability, hence safeguarding the application and its data.
