9
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
Description
OrangeHRM RCE Exploit - CVE-2025-66224 📋 Description This Proof of Concept PoC demonstrates a Remote Code Execution RCE vulnerability in OrangeHRM through command injection in the sendmailpath configuration parameter. The exploit works by: 1. Injecting...
Basic Information
ID
86ACB05D-000A-5E78-88BD-E9E193AAB184
Published
Dec 17, 2025 at 04:40
Modified
Dec 17, 2025 at 04:45