Input Neutralization Vulnerability in OrangeHRM Human Resource Management System
CVE-2025-66224
9CRITICAL
What is CVE-2025-66224?
The OrangeHRM application, specifically from versions 5.0 to 5.7, contains a serious input-neutralization vulnerability within its mail configuration and delivery workflow. This flaw allows uncontrolled user inputs to be processed by the system's sendmail command, leading to potential unauthorized file creation on the server. The lack of input sanitization can unintentionally trigger certain sendmail behaviors that provide an opportunity for attackers to execute malicious content, especially when these files are located in web-accessible directories. This vulnerability has been resolved in version 5.8 of the software.
Affected Version(s)
orangehrm >= 5.0, < 5.8
