The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
References
Link | Resource |
---|---|
https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 | Not Applicable |
https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html | Third Party Advisory |
https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 | Not Applicable |
https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html | Third Party Advisory |
Configurations
History
21 Nov 2024, 06:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 - Not Applicable | |
References | () https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html - Third Party Advisory |
Information
Published : 2021-07-19 12:15
Updated : 2024-11-21 06:12
NVD link : CVE-2021-35966
Mitre link : CVE-2021-35966
CVE.ORG link : CVE-2021-35966
JSON object : View
Products Affected
learningdigital
- orca_hcm
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')