Session Management Flaw in OrangeHRM Human Resource Management System
CVE-2025-66289

8.7HIGH

Key Information:

Vendor

Orangehrm

Status
Vendor
CVE Published:
29 November 2025

What is CVE-2025-66289?

The vulnerability in OrangeHRM affects versions 5.0 to 5.7, where the application fails to invalidate active sessions when user accounts are disabled or passwords are changed. This oversight allows former users or attackers with compromised credentials to retain valid session cookies, granting them uninterrupted access to secure areas of the application. Consequently, despite administrative actions to disable accounts or reset passwords, unauthorized individuals can exploit previously established sessions, posing a significant risk of prolonged unauthorized access and complicating incident response and user management. This critical flaw has been addressed in version 5.8.

Affected Version(s)

orangehrm >= 5.0, < 5.8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.