Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3wg-762h-q86r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

EPSS

Процентиль: 82%
0.01802
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1188
CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

EPSS

Процентиль: 82%
0.01802
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1188
CWE-522