← back
CVE-2021-35963

Learningdigital.com, Inc. Orca HCM - Unrestricted Upload of File with Dangerous Type

CVSS 9.8 CRITICALEPSS 2.4%CWE-434
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 2.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →