CVE Published: 19/07/2021 |
CVE Updated: 17/09/2024 |
CVE Year: 2021 Source: twcert |
Vendor: Learningdigital.com, Inc. |
Product: Orca HCM Status : PUBLISHED
CVE-2021-35968 Description
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N