CVE-2011-5259

SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
orangehrmorangehrm
𝑥
≤ 2.6.11
orangehrmorangehrm
2.6.0
orangehrmorangehrm
2.6.0.1
orangehrmorangehrm
2.6.1
orangehrmorangehrm
2.6.2
orangehrmorangehrm
2.6.3
orangehrmorangehrm
2.6.4
orangehrmorangehrm
2.6.5
orangehrmorangehrm
2.6.6
orangehrmorangehrm
2.6.7
orangehrmorangehrm
2.6.8
orangehrmorangehrm
2.6.8.1
orangehrmorangehrm
2.6.9
orangehrmorangehrm
2.6.10
𝑥
= Vulnerable software versions