Skip to content

Security Report: A Remote Code Execution (RCE) vulnerability exists in icehrm via "/app/install/" #303

@tuando243

Description

@tuando243

A Remote Code Execution (RCE) vulnerability exists in icehrm via "/app/install/".

Step to exploit:

  1. Navigate to IceHRM Installation: http://localhost/icehrm/app/install.
  2. Insert payload "data/icehrm.log');phpinfo();#" to Log file path and then Install Application.
  3. Visit http://localhost/icehrm/app

Screenshot 2022-04-09 at 12 30 49

Screenshot 2022-04-09 at 12 27 51

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions