CVE-2024-8585
EUVD-2024-4928609.09.2024, 03:15
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| learningdigital | orca_hcm | 𝑥 < 11.0 |
𝑥
= Vulnerable software versions