CVE-2025-66289
Last modified
CVE-2025-66289 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Orangehrm | Orangehrm | >= 5.0, < 5.8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66289?
How severe is CVE-2025-66289?
How do I fix CVE-2025-66289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66279A command injection vulnerability has been reported to affec…7.2
- CVE-2025-66280An integer overflow or wraparound vulnerability has been rep…7.2
- CVE-2025-66281A NULL pointer dereference vulnerability has been reported t…7.2
- CVE-2025-66284Stored cross-site scripting vulnerabilities exist in GroupSe…5.4
- CVE-2025-66286An API design flaw in WebKitGTK and WPE WebKit allows untrus…4.7
- CVE-2025-66287A flaw was found in WebKitGTK. Processing malicious web cont…8.8
- CVE-2025-66290OrangeHRM is a comprehensive human resource management (HRM)…4.3
- CVE-2025-66291OrangeHRM is a comprehensive human resource management (HRM)…4.3
- CVE-2025-66292DPanel is an open source server management panel written in …8.1
- CVE-2025-66293LIBPNG is a reference library for use in applications that r…7.1
- CVE-2025-66294Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a…8.8
- CVE-2025-66295Grav is a file-based Web platform. Prior to 1.8.0-beta.27, w…8.8
Are you affected by CVE-2025-66289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
