Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icehrm MEDIUM 6.1
CVE-2023-6282

IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupl…

Mitigation only
Fix from $1,600 2024-01-25
Icehrm MEDIUM 6.5
CVE-2022-26588

A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.ph…

No fix yet
Fix from $1,600 2022-04-08
Icehrm MEDIUM 6.1
CVE-2022-25013

Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the co…

No fix yet
Fix from $1,600 2022-02-28
Icehrm MEDIUM 6.1
CVE-2022-25014

Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the curren…

No fix yet
Fix from $1,600 2022-02-28
Icehrm MEDIUM 5.4
CVE-2022-25015

A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the Firs…

No fix yet
Fix from $1,600 2022-02-28
Icehrm CRITICAL 9.8
CVE-2021-38823

The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session t…

No fix yet
Fix from $2,300 2021-10-04
Icehrm MEDIUM 5.4
CVE-2021-38822

A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary executio…

No fix yet
Fix from $1,600 2021-10-04
Icehrm HIGH 8.8
CVE-2021-34244

A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change u…

No fix yet
Fix from $1,950 2021-06-22
Icehrm MEDIUM 6.1
CVE-2021-35045

Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.

No fix yet
Fix from $1,600 2021-06-22
Icehrm MEDIUM 6.1
CVE-2021-35046

A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session co…

No fix yet
Fix from $1,600 2021-06-22
Icehrm MEDIUM 5.4
CVE-2021-34243

A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML…

No fix yet
Fix from $1,600 2021-06-22
Icehrm HIGH 7.2
CVE-2020-6114

An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538…

No fix yet
Fix from $1,950 2020-07-10
Icehrm HIGH 8.8
CVE-2020-9270

ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.

No fix yet
Fix from $1,950 2020-02-18
Icehrm MEDIUM 6.5
CVE-2020-9271

ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.

No fix yet
Fix from $1,600 2020-02-18
Icehrm HIGH 7.5
CVE-2018-12420

IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.

Fix: 23.0.1.os+
Fix from $1,950 2018-06-14