Vulnerabilities > Simplehrm
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-27 | CVE-2013-2499 | Information Exposure vulnerability in Simplehrm 2.2/2.3 SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie. | 5.0 |
2014-03-01 | CVE-2013-2498 | SQL Injection vulnerability in Simplehrm 2.2/2.3 SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin. | 7.5 |