PT-2021-21084 · Orca Hcm · Orca Hcm

Jia-Rong Chen

·

Published

2021-07-19

·

Updated

2022-10-27

·

CVE-2021-35964

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Orca HCM digital learning platform (affected versions not specified)
Description: The management page of the Orca HCM digital learning platform does not perform identity verification, allowing remote attackers to execute management functions without logging in. This enables attackers to access members' information, modify and delete courses in the system, causing users to fail to access the learning content.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-35964

Affected Products

Orca Hcm