1
I Use This!
Activity Not Available
Analyzed about 1 year ago. based on code collected about 1 year ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2018-12420 High Jun 14, 2018 IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
5.1, 4.2, 4.1, 4.0, 3.2, 3.0.1, v5.3, v5.0, v5.2, 3.0
BDSA-2022-0822 High Mar 29, 2022 IceHrm contains a cross-site request forgery (CSRF) vulnerability due to lack of security measure or tokens. An attacker could exploit this vulnerabili more...
BDSA-2021-4528 High Aug 02, 2022 Ice Hrm is vulnerable to reflected cross-site scripting (XSS) due to the missing sanitization of `m` parameter in the Dashboard of the current user. An more...
BDSA-2021-4527 High Aug 02, 2022 Ice Hrm is vulnerable to reflected cross-site scripting (XSS) due to the missing sanitization of `key` and `fm` parameters in the `login.php` component more...
BDSA-2021-4526 High Aug 02, 2022 Ice Hrm is vulnerable to stored cross-site scripting (XSS) due to the missing sanitization of users' First Name field. An attacker could insert malicio more...
BDSA-2020-1018 High May 07, 2020 IceHrm contains a cross-site request forgery (CSRF) vulnerability in `app/service.php` due to a lack of security measures or CSRF tokens. An attacker c more...
BDSA-2020-1003 High May 07, 2020 IceHrm contains a cross-site request forgery (CSRF) vulnerability in `app/service.php` due to a lack of CSRF tokens. An attacker could exploit this vul more...