The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
References
Link | Resource |
---|---|
https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 | Not Applicable |
https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html | Third Party Advisory |
https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 | Not Applicable |
https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-07-19 12:15
Updated : 2024-11-21 06:12
NVD link : CVE-2021-35966
Mitre link : CVE-2021-35966
CVE.ORG link : CVE-2021-35966
JSON object : View
Products Affected
learningdigital
- orca_hcm
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')