Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2138 | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells |
Solution
For standard user, please update to version 11.0 or later. For customized user, please contact the vendor for updates.
Workaround
No workaround given by the vendor.
Mon, 17 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Learningdigital
Learningdigital orca Hcm |
|
| CPEs | cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Learningdigital
Learningdigital orca Hcm |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Feb 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells | |
| Title | Learning Digital Orca HCM - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-18T15:51:46.400Z
Reserved: 2025-02-17T03:31:38.679Z
Link: CVE-2025-1388
Updated: 2025-02-18T15:51:33.660Z
Status : Analyzed
Published: 2025-02-17T04:15:08.960
Modified: 2025-11-17T13:49:26.427
Link: CVE-2025-1388
No data.
OpenCVE Enrichment
No data.
EUVD