The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
References
Link | Resource |
---|---|
https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25 | Not Applicable |
https://www.twcert.org.tw/tw/cp-132-4926-dc06b-1.html | Third Party Advisory |
Configurations
Information
Published : 2021-07-19 05:15
Updated : 2021-07-28 05:48
NVD link : CVE-2021-35966
Mitre link : CVE-2021-35966
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
learningdigital
- orca_hcm