OWASP ZAP has a basic feature to scan your web application manually step by step to each page that you're expected to find vulnerabilities. In this demo, I tried to scan the login page and navigate to some of the OrangeHRM application modules & pages.
Install your test environment for learning purpose via Docker :
https://hub.docker.com/r/bitnami/oran...