The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22599 The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
Fixes

Solution

Update Orca HCM to version 10.9


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-16T17:54:15.142Z

Reserved: 2021-06-30T00:00:00

Link: CVE-2021-35966

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-19T12:15:08.573

Modified: 2024-11-21T06:12:51.187

Link: CVE-2021-35966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.