Host Header Injection Vulnerability in OrangeHRM by OrangeHRM
CVE-2022-27110

5.4MEDIUM

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
6 April 2022

What is CVE-2022-27110?

OrangeHRM 4.10 contains a vulnerability that allows for a host header injection redirect through the viewPersonalDetails endpoint. This security issue could be exploited by attackers to manipulate the behavior of the application by injecting malicious host headers, potentially leading to unauthorized redirects or accessing sensitive information.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.