go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Learningdigital.com, Inc. Orca HCM - Broken Authentication

TVN ID TVN-202107005
CVE ID CVE-2021-35964
CVSS 7.3 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products Learningdigital.com, Inc. Orca HCM version 10.0
Description The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
Solution Update Orca HCM to version 10.9
Credit Jia-Rong Chen
Public Date 2021-07-19
Top