CVE-2024-8585

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
Configurations

Configuration 1 (hide)

cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*

History

11 Sep 2024, 15:53

Type Values Removed Values Added
CPE cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-8042-f9f26-2.html - () https://www.twcert.org.tw/en/cp-139-8042-f9f26-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8041-dfbf9-1.html - () https://www.twcert.org.tw/tw/cp-132-8041-dfbf9-1.html - Third Party Advisory
First Time Learningdigital orca Hcm
Learningdigital

09 Sep 2024, 13:03

Type Values Removed Values Added
Summary
  • (es) Orca HCM de LEARNING DIGITA no restringe adecuadamente un parámetro específico de la funcionalidad de descarga de archivos, lo que permite que un atacante remoto con privilegios regulares descargue archivos de sistema arbitrarios.

09 Sep 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-09 03:15

Updated : 2024-09-11 15:53


NVD link : CVE-2024-8585

Mitre link : CVE-2024-8585

CVE.ORG link : CVE-2024-8585


JSON object : View

Products Affected

learningdigital

  • orca_hcm
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')