CVE-2021-35968
Last modified
CVE-2021-35968 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Learningdigital | Orca Hcm | <= 10.0 |
References
- https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35968?
How severe is CVE-2021-35968?
How do I fix CVE-2021-35968?
Are you affected by CVE-2021-35968?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
