Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unknown
Any version before 11.0
affected
Description
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version before 11.0
References
www.twcert.org.tw/tw/cp-132-8039-24e48-1.html
www.twcert.org.tw/en/cp-139-8040-948ef-2.html
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.