High severity7.2NVD Advisory· Published May 21, 2025· Updated Jun 17, 2026
CVE-2025-44040
CVE-2025-44040
Description
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions may be made via PHP loose-equality comparisons if a specific MD5 value is present in the credential store. NOTE: this is disputed by the Supplier because an adversary has no way to place the specific MD5 value into the credential store (unless they already have full privileges) and because the specific MD5 value would not realistically be present otherwise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/hexomedin3/advisories/tree/main/CVE-2025-44040nvdThird Party Advisory
- github.com/orangehrm/orangehrm/releases/tag/v5.7nvdRelease Notes
News mentions
0No linked articles in our index yet.