CVE-2021-35964

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-07-19 12:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-35964

Mitre link : CVE-2021-35964

CVE.ORG link : CVE-2021-35964


JSON object : View

Products Affected

learningdigital

  • orca_hcm
CWE
CWE-287

Improper Authentication

CWE-285

Improper Authorization