Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Orangehrm 安全漏洞
Vulnerability Description
Orangehrm是美国Orangehrm公司的一套人力资源管理系统(HRM)。该系统支持人事信息管理、休假管理、考勤管理和招聘管理等功能。 Orangehrm 4.10 版本存在安全漏洞,该漏洞源于 symfony/web/index.php/time/createTimesheet 存在不安全直接对象引用(IDOR:Insecure direct object references)。通过验证的攻击者可以在另一个用户的帐户中创建时间表。
CVSS Information
N/A
Vulnerability Type
N/A