漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion
Vulnerability Description
OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.
CVSS Information
N/A
Vulnerability Type
授权机制不恰当
Vulnerability Title
OrangeHRM 授权问题漏洞
Vulnerability Description
OrangeHRM是美国OrangeHRM公司的一套人力资源管理系统(HRM)。该系统支持人事信息管理、休假管理、考勤管理和招聘管理等功能。 OrangeHRM 5.8及之前版本存在授权问题漏洞,该漏洞源于允许管理员用户在自我评估提交完成后更改内容,可能破坏最终评估记录的完整性。
CVSS Information
N/A
Vulnerability Type
N/A