CVE-2024-8584
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: twcert@cert.org.tw (Secondary)
Description
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Affected (1)
Products: Learningdigital: Orca Hcm
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.0 |
References (2)
Timeline
No history available yet.