VYPR
High severity8.8NVD Advisory· Published Jun 15, 2019· Updated Jun 17, 2026

CVE-2019-12839

CVE-2019-12839

Description

In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*range: <=4.3.1
    • (no CPE)range: <=4.3.1
  • OrangeHRM/OrangeHRMdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.