CRITICAL🇵🇱 Wersja polska

CVE-2021-35963

CVSS 9.8v3.1pub. 2021-07-19upd. 2024-11-21

The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Learningdigital Orca Hcm

    APP
    Learningdigital
    ≤ 10.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-1387CRITICAL9.8PL ✓same product

Orca HCM — Improper Authentication umożliwiające logowanie jako dowolny użytkownik

CVE-2024-8584CRITICAL9.8PL ✓same product

Orca HCM: brak uwierzytelnienia umożliwia tworzenie kont administratora

CVE-2021-35965CRITICAL9.8PL ✓same product

Orca HCM: zakodowane domyślne hasło administratora w kodzie źródłowym

CVE-2025-1389HIGH8.8same product

Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges t...

CVE-2025-1388HIGH8.8same product

Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regu...