PT-2025-48366 · Orangehrm · Orangehrm

Published

2025-11-29

·

Updated

2025-11-29

·

CVE-2025-66225

CVSS v4.0
8.7
VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OrangeHRM versions 5.0 through 5.7
Description OrangeHRM is a human resource management system. A flaw exists in the password reset workflow where the system does not verify that the
username
submitted in the final reset request matches the account initiating the process. An attacker can modify the
username
parameter in the request to target a different user and successfully set a new password, leading to full account takeover, including privileged accounts. This affects versions 5.0 through 5.7. The issue is resolved in version 5.8.
Recommendations Upgrade to OrangeHRM version 5.8 or later.

Fix

Insufficient Verification of Data Authenticity

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-66225
GHSA-5GHW-9775-V263

Affected Products

Orangehrm