ZeroHour

CVE-2024-8584

CVSS 3.1
9.8 critical
EPSS
<1%p50
Published
()
Modified
Description

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

Vendors
learningdigital
Products
orca hcm
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.