The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-07-19T11:55:43.534568Z
Updated: 2024-09-16T17:54:15.142Z
Reserved: 2021-06-30T00:00:00
Link: CVE-2021-35966
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-19T12:15:08.573
Modified: 2024-11-21T06:12:51.187
Link: CVE-2021-35966
Redhat
No data.