High severity8.1NVD Advisory· Published Jan 5, 2021· Updated Jun 17, 2026
CVE-2020-29437
CVE-2020-29437
Description
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OrangeHRM/OrangeHRMdescription
Patches
Vulnerability mechanics
References
4- github.com/orangehrm/orangehrm/pull/699nvdPatchThird Party Advisory
- www.horizon3.ai/disclosures/orangehrm-sqli.htmlnvdExploitThird Party Advisory
- github.com/orangehrm/orangehrm/issues/695nvdThird Party Advisory
- github.com/orangehrm/orangehrm/releasesnvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.