Release date:
Updated on:
Affected Systems:
OrangeHRM 2.x
Description:
--------------------------------------------------------------------------------
OrangeHRM is a comprehensive human resource management (HRM) system. It implements some important HR functions required by any enterprise.
OrangeHRM has a security vulnerability. Attackers can exploit this vulnerability to control affected systems.
The input of the "path" parameter passed to plugins/PluginController. php is not correctly verified before being used to include files, resulting in arbitrary files containing local or external resources.
<* Source: AutoSec Tools
Link: http://www.autosectools.com/Advisory/OrangeHRM-2.6.3-Local-File-Inclusion-189
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OrangeHRM
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.orangehrm.com/