Vulnerability Description
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Learningdigital | Orca Hcm | <= 10.0 |
Related Weaknesses (CWE)
References
- https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25Not Applicable
- https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25Not Applicable
- https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.htmlThird Party Advisory
FAQ
What is CVE-2021-35968?
CVE-2021-35968 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users...
How severe is CVE-2021-35968?
CVE-2021-35968 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35968?
Check the references section above for vendor advisories and patch information. Affected products include: Learningdigital Orca Hcm.