CVE-2021-35963

CRITICAL

Orca HCM < 10.0 - Unauthenticated Remote Code Execution via File Upload

Title source: llm
STIX 2.1

Description

The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-4923-d68e6-1.html

Scores

CVSS v3 9.8
EPSS 0.0241
EPSS Percentile 82.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
learningdigital/orca_hcm < 10.0
Published Jul 19, 2021
Tracked Since Feb 18, 2026