OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vulnerability is fixed in 5.8.1.
References
| Link | Resource |
|---|---|
| https://github.com/orangehrm/orangehrm/security/advisories/GHSA-xq24-qv66-9v3m | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-07 19:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-39345
Mitre link : CVE-2026-39345
CVE.ORG link : CVE-2026-39345
JSON object : View
Products Affected
orangehrm
- orangehrm
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
