CVE-2022-27108
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/cre
OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another user's account.
MEDIUM · CVSS 4.3
EPSS 0.00134
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0