go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Learning Digital Orca HCM - SQL Injection

TVN ID TVN-202502006
CVE ID CVE-2025-1389
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Orca HCM before version 11.0
Description Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution For standard user, please update to version 11.0 or later.
For customized user, please contact the vendor for updates.
Credit Vtim(DEVCORE)
Public Date 2025-02-17
Top