The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLearningdigital Orca Hcm
APPLearningdigital≤ 10.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2025-1387CRITICAL9.8PL ✓same product
Orca HCM — Improper Authentication umożliwiające logowanie jako dowolny użytkownik
CVE-2024-8584CRITICAL9.8PL ✓same product
Orca HCM: brak uwierzytelnienia umożliwia tworzenie kont administratora
CVE-2021-35965CRITICAL9.8PL ✓same product
Orca HCM: zakodowane domyślne hasło administratora w kodzie źródłowym
CVE-2025-1389HIGH8.8same product
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges t...
CVE-2025-1388HIGH8.8same product
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regu...