Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2139 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. |
Solution
For standard user, please update to version 11.0 or later. For customized user, please contact the vendor for updates.
Workaround
No workaround given by the vendor.
Mon, 17 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Learningdigital
Learningdigital orca Hcm |
|
| CPEs | cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Learningdigital
Learningdigital orca Hcm |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Feb 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Title | Learning Digital Orca HCM - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-18T15:32:37.068Z
Reserved: 2025-02-17T03:31:39.867Z
Link: CVE-2025-1389
Updated: 2025-02-18T15:32:25.336Z
Status : Analyzed
Published: 2025-02-17T05:15:10.317
Modified: 2025-11-17T13:48:16.930
Link: CVE-2025-1389
No data.
OpenCVE Enrichment
No data.
EUVD