Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8584

Опубликовано: 09 сент. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*:*
Версия до 11.0 (исключая)

EPSS

Процентиль: 69%
0.0061
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306
NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

Orca HCM from LEARNING DIGITAL does not properly restrict access to a specific functionality, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.

EPSS

Процентиль: 69%
0.0061
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-306
NVD-CWE-Other