CVE-2021-35963
Learningdigital.com, Inc. Orca HCM - Unrestricted Upload of File with Dangerous Type
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 2.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Learningdigital.com, Inc. · Orca HCMWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →