1
I Use This!
Very Low Activity
Analyzed 1 day ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2018-12420 High Jun 14, 2018 IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
5.1, 4.2, 4.1, 4.0, 3.2, 3.0.1, v5.3, v5.0, v5.2, 3.0
BDSA-2025-0070 High Jan 07, 2025 A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization o more...
BDSA-2022-0822 High Mar 29, 2022 IceHrm contains a cross-site request forgery (CSRF) vulnerability due to lack of security measure or tokens. An attacker could exploit this vulnerabili more...
BDSA-2021-4528 High Aug 02, 2022 Ice Hrm is vulnerable to reflected cross-site scripting (XSS) due to the missing sanitization of `m` parameter in the Dashboard of the current user. An more...
BDSA-2021-4527 High Aug 02, 2022 Ice Hrm is vulnerable to reflected cross-site scripting (XSS) due to the missing sanitization of `key` and `fm` parameters in the `login.php` component more...
BDSA-2021-4526 High Aug 02, 2022 Ice Hrm is vulnerable to stored cross-site scripting (XSS) due to the missing sanitization of users' First Name field. An attacker could insert malicio more...
BDSA-2020-1018 High May 07, 2020 IceHrm contains a cross-site request forgery (CSRF) vulnerability in `app/service.php` due to a lack of security measures or CSRF tokens. An attacker c more...
BDSA-2020-1003 High May 07, 2020 IceHrm contains a cross-site request forgery (CSRF) vulnerability in `app/service.php` due to a lack of CSRF tokens. An attacker could exploit this vul more...