CVE-2021-35967

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/07/2021
Last modified:
29/07/2021

Description

The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:* 10.0 (including)