Total vulnerabilities in the database
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.
Software | From | Fixed in |
---|---|---|
orangehrm / orangehrm | - | 4.3.1.x |