Referer Header Injection Vulnerability in OrangeHRM by OrangeHRM
CVE-2022-27109

5.4MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
6 April 2022

What is CVE-2022-27109?

OrangeHRM version 4.10 is susceptible to a referer header injection redirect vulnerability, which can allow unauthorized users to manipulate web requests. This security flaw could enable attackers to redirect users or exploit session management weaknesses, potentially leading to unauthorized access or data exposure. It's crucial for users of the affected software to be aware of this vulnerability and take preventive measures to safeguard their systems.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.