Skip to main content
Vulnerability Database/CVE-2025-66290

CVE-2025-66290: OrangeHRM Information Disclosure Flaw

CVE-2025-66290 is an information disclosure vulnerability in OrangeHRM that allows unauthorized users to access candidate recruitment files. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2025-66290 Overview

CVE-2025-66290 is a broken access control vulnerability in OrangeHRM, an open-source human resource management system. Versions 5.0 through 5.7 fail to enforce authorization checks on the recruitment attachment retrieval endpoint. Any authenticated user, including those restricted to Employee Self-Service (ESS) roles, can download candidate CVs and uploaded documents by issuing direct requests to the attachment endpoint. The endpoint validates the session but does not verify recruitment module permissions. This exposes sensitive applicant data such as resumes, cover letters, and personally identifiable information (PII) to users who should have no access to the Recruitment module. The issue is tracked under [CWE-200: Exposure of Sensitive Information to an Unauthorized Actor].

Critical Impact

Any authenticated OrangeHRM user, including low-privilege ESS accounts, can download recruitment attachments for arbitrary candidates, exposing CVs and applicant PII.

Affected Products

  • OrangeHRM version 5.0
  • OrangeHRM versions 5.1 through 5.6
  • OrangeHRM version 5.7

Discovery Timeline

  • 2025-11-29 - CVE-2025-66290 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66290

Vulnerability Analysis

OrangeHRM exposes an endpoint that serves candidate attachment files uploaded through the Recruitment module. The endpoint performs session validation to confirm the requester is authenticated. It does not perform a follow-up authorization check to confirm the session belongs to a user with recruitment permissions. This gap allows horizontal and vertical access boundaries to be bypassed within the application.

An ESS-level user has no legitimate visibility into the Recruitment module through the UI. However, by supplying valid attachment identifiers to the endpoint, that same user retrieves file content directly. The vulnerability exposes structured HR data, including candidate resumes and supporting documents, which frequently contain names, contact details, employment history, and government identifiers.

Root Cause

The root cause is a missing authorization check on a data-serving endpoint. Authentication is confirmed, but the application does not evaluate whether the authenticated principal holds the Recruitment module permission before returning file bytes. This is a classic Broken Access Control pattern, mapped to [CWE-200].

Attack Vector

Exploitation requires only network access to the OrangeHRM instance and any valid user session. An attacker with an ESS account, or any compromised low-privilege account, issues authenticated HTTP GET requests to the recruitment attachment endpoint using iterated or discovered attachment identifiers. The server returns the attachment content without checking module authorization, enabling bulk collection of candidate documents.

No exploit code or public proof-of-concept is listed in the enriched data for this issue. Technical detail is available in the OrangeHRM GitHub Security Advisory GHSA-qf8r-c54j-jw88.

Detection Methods for CVE-2025-66290

Indicators of Compromise

  • Requests to the recruitment attachment endpoint originating from user sessions that do not belong to HR or recruiter roles.
  • Sequential or enumerated attachment identifier values in access logs, suggesting ID iteration.
  • Unusual volumes of file downloads from a single authenticated ESS session within a short window.
  • HTTP 200 responses returning file MIME types (PDF, DOCX) to accounts with no recruitment role assignment.

Detection Strategies

  • Correlate application access logs with user role assignments to identify authenticated file retrievals by users lacking Recruitment permissions.
  • Deploy a Web Application Firewall (WAF) rule that inspects requests to the recruitment attachment path and flags requesters whose session role is not on an allowlist.
  • Baseline normal document download rates per role, and alert on statistical deviations.

Monitoring Recommendations

  • Forward OrangeHRM web server and application logs to a centralized log platform for retention and query.
  • Enable audit logging on the Recruitment module and review candidate document access events daily until patched.
  • Monitor authentication logs for creation of new low-privilege accounts followed by immediate access to attachment URLs.

How to Mitigate CVE-2025-66290

Immediate Actions Required

  • Upgrade OrangeHRM to version 5.8 or later, which contains the vendor fix.
  • Inventory all OrangeHRM instances, including staging and test deployments, and confirm each version.
  • Rotate credentials for any low-privilege accounts suspected of unauthorized access to recruitment attachments.
  • Notify recruitment stakeholders and, where required by regulation, prepare data breach notification workflows for exposed applicant PII.

Patch Information

OrangeHRM addressed the issue in version 5.8. The fix enforces recruitment module authorization on the attachment retrieval endpoint before returning file content. Details are documented in the OrangeHRM GitHub Security Advisory GHSA-qf8r-c54j-jw88.

Workarounds

  • Restrict network access to the OrangeHRM instance to trusted corporate networks or VPN users until the upgrade is completed.
  • Temporarily disable or limit ESS account provisioning to reduce the population of low-privilege accounts that could exploit the endpoint.
  • Place a reverse proxy or WAF rule in front of OrangeHRM that blocks unauthenticated and non-recruiter access to the recruitment attachment endpoint path.
  • Audit recent recruitment attachment access logs and revoke any suspicious sessions.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.