ZeroHour

CVE-2021-35964

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.

Vendors
learningdigital
Products
orca hcm
Weakness
CWE-285, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.