go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Learning Digital Orca HCM - Arbitrary File Upload

TVN ID TVN-202502005
CVE ID CVE-2025-1388
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Orca HCM before version 11.0
Description Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells.
Solution For standard user, please update to version 11.0 or later.
For customized user, please contact the vendor for updates.
Credit Vtim(DEVCORE)
Public Date 2025-02-17
Top