Session Management Flaw in OrangeHRM Human Resource Management System
CVE-2025-66289
8.7HIGH
What is CVE-2025-66289?
The vulnerability in OrangeHRM affects versions 5.0 to 5.7, where the application fails to invalidate active sessions when user accounts are disabled or passwords are changed. This oversight allows former users or attackers with compromised credentials to retain valid session cookies, granting them uninterrupted access to secure areas of the application. Consequently, despite administrative actions to disable accounts or reset passwords, unauthorized individuals can exploit previously established sessions, posing a significant risk of prolonged unauthorized access and complicating incident response and user management. This critical flaw has been addressed in version 5.8.
Affected Version(s)
orangehrm >= 5.0, < 5.8
