Horizon3.ai
Horizon3.ai

Disclosures

Filters

Tags

Showing 19–19 of 19 results

CVE-2020-29437: Authenticated SQL Injection in OrangeHRM < 4.6.0.1

OrangeHRM is software for Human Resource Management (HRM). In a routine audit of the open source version of OrangeHRM, we discovered a SQL injection vulnerability in the "Buzz" module, an integrated social media tool within the software. Authenticated low privilege users can use this vulnerability to disclose the full contents of the OrangeHRM database, including sensitive user personal information and...
Read More

How can NodeZero help you?

Let our experts walk you through a demonstration of NodeZero, so you can see how to put it to work for your company.