Skip to main content
Vulnerability Database/CVE-2025-66291

CVE-2025-66291: OrangeHRM Information Disclosure Flaw

CVE-2025-66291 is an information disclosure vulnerability in OrangeHRM that exposes confidential interview documents to unauthorized users. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2025-66291 Overview

CVE-2025-66291 is an Insecure Direct Object Reference (IDOR) vulnerability in OrangeHRM, an open-source human resource management (HRM) system. The flaw affects the interview attachment retrieval endpoint in the Recruitment module across versions 5.0 through 5.7. The endpoint serves files based on an authenticated session and user-supplied identifiers without verifying whether the requester has permission to access the associated interview record. An Employee Self-Service (ESS) user without recruitment permissions can request interview attachment URLs directly and receive confidential files, including candidate CVs, evaluations, and supporting documents. The issue is patched in version 5.8.

Critical Impact

Authenticated low-privilege users can retrieve confidential recruitment attachments—including candidate CVs and interview evaluations—by iterating predictable object identifiers.

Affected Products

  • OrangeHRM 5.0 through 5.7
  • OrangeHRM Recruitment module (orangehrmRecruitmentPlugin)
  • Interview attachment endpoint handled by InterviewAttachment controller

Discovery Timeline

  • 2025-11-29 - CVE-2025-66291 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66291

Vulnerability Analysis

The vulnerability is a classic Insecure Direct Object Reference (IDOR) mapped to [CWE-200] Information Exposure. The InterviewAttachment controller in the OrangeHRM\Recruitment\Controller\File namespace served files whenever a valid session existed and a numeric attachment identifier was supplied. The controller never checked whether the requesting user had a legitimate association with the parent interview or the recruitment workflow. Because attachment identifiers are sequential integers, an attacker can enumerate values and download every stored interview file. Exposed data includes candidate resumes, hiring manager evaluations, and any supplementary documents uploaded during recruitment. The vulnerability is exploitable over the network by any authenticated user, including standard ESS employees who have no legitimate business with the Recruitment module.

Root Cause

The root cause is missing recruitment-level authorization on a file-serving endpoint. The controller depended on session presence and object identifiers rather than validating the user's role and their relationship to the interview record. The trust boundary between ESS and recruitment functions was not enforced at the resource layer.

Attack Vector

An attacker authenticates to OrangeHRM as any low-privilege user, such as a standard employee with ESS access. They then send requests to the interview attachment endpoint while iterating the numeric attachment ID. The server returns the raw file for each valid ID without checking permissions.

php
// Patch excerpt: src/plugins/orangehrmRecruitmentPlugin/Controller/File/InterviewAttachment.php
namespace OrangeHRM\Recruitment\Controller\File;

use OrangeHRM\Authentication\Exception\ForbiddenException;
use OrangeHRM\Core\Controller\AbstractFileController;
use OrangeHRM\Core\Traits\UserRoleManagerTrait;
use OrangeHRM\Entity\Interview;
use OrangeHRM\Framework\Http\Request;
use OrangeHRM\Framework\Http\Response;
use OrangeHRM\Recruitment\Traits\Service\RecruitmentAttachmentServiceTrait;

class InterviewAttachment extends AbstractFileController
{
    use RecruitmentAttachmentServiceTrait;
    use UserRoleManagerTrait;

    public function handle(Request $request): Response
    {
        // Added authorization check via UserRoleManager and ForbiddenException
    }
}

Source: OrangeHRM patch commit 647133d. The fix introduces the UserRoleManagerTrait and imports ForbiddenException and the Interview entity so the controller can verify the caller's role against the target interview before returning file contents.

Detection Methods for CVE-2025-66291

Indicators of Compromise

  • HTTP requests to interview attachment routes originating from user accounts that lack Admin or Hiring Manager roles.
  • Sequential enumeration of the numeric id parameter on interview attachment URLs from a single session or source IP.
  • Unusually high volume of file downloads from the Recruitment module by ESS-only accounts.

Detection Strategies

  • Review OrangeHRM web server access logs for the InterviewAttachment controller path and correlate the requesting user's role from the application database.
  • Alert on any successful 200 response to interview attachment endpoints where the session belongs to a user without recruitment privileges.
  • Baseline normal recruitment file access patterns and flag deviations, especially bursts of downloads across many distinct attachment IDs.

Monitoring Recommendations

  • Forward OrangeHRM application and web server logs to a centralized SIEM for role-aware correlation.
  • Enable database query logging on the ohrm_interview_attachment table and alert on access from unexpected application contexts.
  • Track authentication events for ESS accounts that suddenly begin interacting with recruitment endpoints.

How to Mitigate CVE-2025-66291

Immediate Actions Required

  • Upgrade OrangeHRM to version 5.8 or later, which contains the authorization fix in commit 647133d.
  • Audit web server logs for prior access to interview attachment URLs by non-recruitment users and notify affected candidates if data exposure is confirmed.
  • Rotate or invalidate active user sessions after applying the patch to force re-authentication.

Patch Information

The vendor released the fix in OrangeHRM 5.8. The corrective commit adds UserRoleManagerTrait to the InterviewAttachment controller and enforces recruitment-level authorization before serving files, throwing a ForbiddenException for unauthorized callers. See the GitHub Security Advisory GHSA-v32g-r8xx-4g6g and the patch commit for full details.

Workarounds

  • Restrict network access to the OrangeHRM Recruitment module using a reverse proxy or web application firewall rule that limits interview attachment paths to trusted user groups until patching is complete.
  • Temporarily disable the Recruitment module for tenants that cannot upgrade immediately.
  • Enforce least-privilege review of all user accounts to ensure ESS-only users have no elevated recruitment permissions granted in error.
bash
# Example nginx rule to restrict interview attachment access to internal HR network until patched
location ~* /recruitment/.*interviewAttachment {
    allow 10.10.20.0/24;   # HR staff subnet
    deny all;
    proxy_pass http://orangehrm_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.