CVE-2024-8585

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
09/09/2024
Last modified:
11/09/2024

Description

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:* 11.0 (excluding)