ZeroHour

CVE-2021-35966

CVSS 3.1
6.1 medium
EPSS
<1%p55
Published
()
Modified
Description

The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.

Vendors
learningdigital
Products
orca hcm
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.