CVE-2021-35964

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:12

Type Values Removed Values Added
References () https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 - Third Party Advisory () https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-4924-f74d5-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-4924-f74d5-1.html - Third Party Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 7.3

Information

Published : 2021-07-19 12:15

Updated : 2024-11-21 06:12


NVD link : CVE-2021-35964

Mitre link : CVE-2021-35964

CVE.ORG link : CVE-2021-35964


JSON object : View

Products Affected

learningdigital

  • orca_hcm
CWE
CWE-285

Improper Authorization

CWE-287

Improper Authentication