CVE-2021-35967
19.07.2021, 12:15
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.
Vendor | Product | Version |
---|---|---|
learningdigital | orca_hcm | 𝑥 ≤ 10.0 |
𝑥
= Vulnerable software versions