CVE-2021-35963

CRITICAL

Orca HCM - RCE

Title source: llm
STIX 2.1

Description

The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4923-d68e6-1.html

Scores

CVSS v3 9.8
EPSS 0.0211
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
learningdigital/orca_hcm < 10.0
Published Jul 19, 2021
Tracked Since Feb 18, 2026