CVE-2011-5259

EUVD-2011-5158
SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
orangehrmorangehrm
𝑥
≤ 2.6.11
orangehrmorangehrm
2.6.0
orangehrmorangehrm
2.6.0.1
orangehrmorangehrm
2.6.1
orangehrmorangehrm
2.6.2
orangehrmorangehrm
2.6.3
orangehrmorangehrm
2.6.4
orangehrmorangehrm
2.6.5
orangehrmorangehrm
2.6.6
orangehrmorangehrm
2.6.7
orangehrmorangehrm
2.6.8
orangehrmorangehrm
2.6.8.1
orangehrmorangehrm
2.6.9
orangehrmorangehrm
2.6.10
𝑥
= Vulnerable software versions