Account Takeover Vulnerability in OrangeHRM Human Resource Management System
CVE-2025-66225
8.7HIGH
What is CVE-2025-66225?
The OrangeHRM system versions 5.0 to 5.7 have a vulnerability in the password reset workflow that allows an attacker to take over accounts. The flaw stems from the failure to validate the username in the final reset request against the original account. An attacker, after obtaining a valid reset link, can manipulate the username parameter to target another user's account and set a new password without proper verification, potentially allowing them to gain access to sensitive information and privileges. This vulnerability has been addressed in version 5.8.
Affected Version(s)
orangehrm >= 5.0, < 5.8
