Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Feb 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Mon, 17 Feb 2025 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. ( The vendor is currently addressing the vulnerability. Once the fix is completed, we will provide information on the affected versions.) | Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. |
Title | LEARNING DIGITAL Orca HCM - Improper Access Control | LEARNING DIGITAL Orca HCM - Missing Authentication |
Weaknesses | CWE-306 |
Fri, 13 Sep 2024 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. | Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. ( The vendor is currently addressing the vulnerability. Once the fix is completed, we will provide information on the affected versions.) |
Wed, 11 Sep 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-Other |
Mon, 09 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Learningdigital
Learningdigital orca Hcm |
|
CPEs | cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Learningdigital
Learningdigital orca Hcm |
|
Metrics |
ssvc
|
Mon, 09 Sep 2024 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. | |
Title | LEARNING DIGITAL Orca HCM - Improper Access Control | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-21T16:54:03.087Z
Reserved: 2024-09-09T02:28:07.857Z
Link: CVE-2024-8584

Updated: 2024-09-09T13:40:39.001Z

Status : Modified
Published: 2024-09-09T03:15:09.723
Modified: 2025-02-17T04:15:08.240
Link: CVE-2024-8584

No data.