CVE-2025-44040 | OrangeHRM 5.7 UserService.php checkFOrOldHash privilege escalation
A vulnerability, which was classified as problematic, was found in OrangeHRM 5.7. Affected is the function checkFOrOldHash of the file UserService.php. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2025-44040. The attack needs to be initiated within the local network. There is no exploit available.