VYPR

Icehrm

by gamonoid

Source repositories

CVEs (3)

  • CVE-2024-46073MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this…

  • CVE-2026-15478MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employeeList can lead to sql injection. The attack…

  • CVE-2018-12420HigJun 14, 2018
    risk 0.00cvss 7.5epss 0.01

    IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.