The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-07-19T11:55:43.534568Z

Updated: 2024-09-16T17:54:15.142Z

Reserved: 2021-06-30T00:00:00

Link: CVE-2021-35966

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-07-19T12:15:08.573

Modified: 2021-07-28T12:48:22.047

Link: CVE-2021-35966

cve-icon Redhat

No data.