Vulnerability Details CVE-2007-5931
The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2007-5931
-
cpe:2.3:a:orangehrm:orangehrm:-
-
cpe:2.3:a:orangehrm:orangehrm:2.1
-
cpe:2.3:a:orangehrm:orangehrm:2.2.0.2
-
cpe:2.3:a:orangehrm:orangehrm:2.2.0.3
-
cpe:2.3:a:orangehrm:orangehrm:2.2.1