CVE-2021-35964

The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*

History

27 Oct 2022, 12:25

Type Values Removed Values Added
CWE CWE-285 CWE-287

28 Jul 2021, 12:40

Type Values Removed Values Added
CWE CWE-285
CPE cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
References (MISC) https://www.twcert.org.tw/tw/cp-132-4924-f74d5-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-4924-f74d5-1.html - Third Party Advisory
References (MISC) https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 - (MISC) https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 - Third Party Advisory

19 Jul 2021, 12:36

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-19 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-35964

Mitre link : CVE-2021-35964

CVE.ORG link : CVE-2021-35964


JSON object : View

Products Affected

learningdigital

  • orca_hcm
CWE
CWE-287

Improper Authentication

CWE-285

Improper Authorization