icehrm
by IceHrm
CVEs (17)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38823 | Cri | 0.64 | 9.8 | 0.02 | Oct 4, 2021 | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser. | ||
| CVE-2021-34244 | Hig | 0.57 | 8.8 | 0.01 | Jun 22, 2021 | A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords. | ||
| CVE-2020-9270 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2020 | ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php. | ||
| CVE-2020-6114 | Hig | 0.47 | 7.2 | 0.02 | Jul 10, 2020 | An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to… | ||
| CVE-2022-26588 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2022 | A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI. | ||
| CVE-2020-9271 | Med | 0.42 | 6.5 | 0.00 | Feb 18, 2020 | ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php. | ||
| CVE-2024-46073 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this… | ||
| CVE-2022-25014 | Med | 0.40 | 6.1 | 0.01 | Feb 28, 2022 | Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link. | ||
| CVE-2022-25013 | Med | 0.40 | 6.1 | 0.01 | Feb 28, 2022 | Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php. | ||
| CVE-2021-35046 | Med | 0.40 | 6.1 | 0.01 | Jun 22, 2021 | A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie. | ||
| CVE-2021-35045 | Med | 0.40 | 6.1 | 0.01 | Jun 22, 2021 | Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint. | ||
| CVE-2023-6282 | Med | 0.35 | 5.4 | 0.00 | Jan 25, 2024 | IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript… | ||
| CVE-2022-25015 | Med | 0.35 | 5.4 | 0.01 | Feb 28, 2022 | A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field. | ||
| CVE-2021-38822 | Med | 0.35 | 5.4 | 0.01 | Oct 4, 2021 | A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands. | ||
| CVE-2021-34243 | Med | 0.35 | 5.4 | 0.01 | Jun 22, 2021 | A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of… | ||
| CVE-2026-15478 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack… | ||
| CVE-2018-12420 | Hig | 0.00 | 7.5 | 0.01 | Jun 14, 2018 | IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request. |
- risk 0.64cvss 9.8epss 0.02
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.
- risk 0.57cvss 8.8epss 0.01
A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change users' passwords.
- risk 0.57cvss 8.8epss 0.01
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
- risk 0.47cvss 7.2epss 0.02
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to…
- risk 0.42cvss 6.5epss 0.01
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
- risk 0.42cvss 6.5epss 0.00
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
- risk 0.40cvss 6.1epss 0.00
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this…
- risk 0.40cvss 6.1epss 0.01
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.
- risk 0.40cvss 6.1epss 0.01
Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.
- risk 0.40cvss 6.1epss 0.01
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.
- risk 0.40cvss 6.1epss 0.01
Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.
- risk 0.35cvss 5.4epss 0.00
IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this vulnerability by sending a specially crafted JavaScript…
- risk 0.35cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.
- risk 0.35cvss 5.4epss 0.01
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.
- risk 0.35cvss 5.4epss 0.01
A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of…
- risk 0.00cvss 6.3epss 0.00
A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack…
- risk 0.00cvss 7.5epss 0.01
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.