{"id":"CVE-2025-66289","summary":"OrangeHRM is Vulnerable to Persistent Session Access Due to Missing Invalidation After User Disable and Password Change","details":"OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.","aliases":["GHSA-99qp-xh4q-pr9x"],"modified":"2026-08-12T03:51:36.314179426Z","published":"2025-11-29T03:06:25.730Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-613"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66289.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66289.json"},{"type":"ADVISORY","url":"https://github.com/orangehrm/orangehrm/security/advisories/GHSA-99qp-xh4q-pr9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66289"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/orangehrm/orangehrm","events":[{"introduced":"7bd109532b98fbf2896627b86099cc82afe215fb"},{"fixed":"d3815c0d746f1484d76e3d59d25ae55f48edd9fa"}],"database_specific":{"cpe":"cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.0"},{"fixed":"5.8"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v5.7","v5.6.1","v5.6","v5.5","v5.4","v5.3","v5.2","v5.1","v.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66289.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}