Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
learningdigital orca hcm vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-35965
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
Learningdigital Orca Hcm
6.1
CVSSv3
CVE-2021-35966
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
Learningdigital Orca Hcm
5.3
CVSSv3
CVE-2021-35967
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.
Learningdigital Orca Hcm
4.3
CVSSv3
CVE-2021-35968
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.
Learningdigital Orca Hcm
9.8
CVSSv3
CVE-2021-35963
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated malicious users to upload files containing malicious script to execute RCE attacks.
Learningdigital Orca Hcm
9.8
CVSSv3
CVE-2021-35964
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote malicious users to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causin...
Learningdigital Orca Hcm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started