Input Neutralization Vulnerability in OrangeHRM Human Resource Management System
CVE-2025-66224

9CRITICAL

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
29 November 2025

What is CVE-2025-66224?

The OrangeHRM application, specifically from versions 5.0 to 5.7, contains a serious input-neutralization vulnerability within its mail configuration and delivery workflow. This flaw allows uncontrolled user inputs to be processed by the system's sendmail command, leading to potential unauthorized file creation on the server. The lack of input sanitization can unintentionally trigger certain sendmail behaviors that provide an opportunity for attackers to execute malicious content, especially when these files are located in web-accessible directories. This vulnerability has been resolved in version 5.8 of the software.

Affected Version(s)

orangehrm >= 5.0, < 5.8

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.