The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26351 | vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38245 | vdb entry |
http://sourceforge.net/project/shownotes.php?release_id=550550&group_id=156477 | patch |
http://www.vupen.com/english/advisories/2007/3719 | vdb entry |
http://osvdb.org/45295 | vdb entry |