Releases35
Frequency3 months 3 weeks
Last Release
Stars710
Manage your employees easily with a robust and efficient Human Resource Management System

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.

6.1 MEDIUM4.3 MEDIUM

Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.

5.4 MEDIUM3.5 LOW

A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.

5 MEDIUM

IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.