CVE-2022-27110
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
MEDIUM · CVSS 5.4
EPSS 0.00134
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0