PT-2021-21084 · Orca Hcm · Orca Hcm
Jia-Rong Chen
·
Published
2021-07-19
·
Updated
2022-10-27
·
CVE-2021-35964
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Orca HCM digital learning platform (affected versions not specified)
Description:
The management page of the Orca HCM digital learning platform does not perform identity verification, allowing remote attackers to execute management functions without logging in. This enables attackers to access members' information, modify and delete courses in the system, causing users to fail to access the learning content.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Orca Hcm