CVE-2011-5258
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitr
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.6.11.2 allow remote attackers to inject arbitrary web script or HTML via the (1) uniqcode or (2) isAdmin parameter to index.php.
or the (3) PATH_INFO to lib/controllers/centralcontroller.php.
MEDIUM · CVSS 4.3
EPSS 0.065
Schedule remediation
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0