Icehrm
by gamonoid
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-46073 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this… | ||
| CVE-2026-15478 | Med | 0.00 | 6.3 | 0.00 | Jul 12, 2026 | A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack… | ||
| CVE-2018-12420 | Hig | 0.00 | 7.5 | 0.01 | Jun 14, 2018 | IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request. |
- risk 0.40cvss 6.1epss 0.00
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this…
- risk 0.00cvss 6.3epss 0.00
A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack…
- risk 0.00cvss 7.5epss 0.01
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.