Secunia Security Advisory – Some vulnerabilities have been discovered in OrangeHRM, which can be exploited by malicious users to conduct script insertion and SQL injection attacks and by malicious people to conduct cross-site scripting, cross-site request forgery, and script insertion attacks.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89466/sa39795.txt
Source: https://packetstormsecurity.com/files/89466/Secunia-Security-Advisory-39795.html