Learning Digital Orca HCM
cpe:2.3:a:learningdigital:orca_hcm:*:*:*:*:*:*:*
- < 11.0
An arbitrary file upload vulnerability has been identified in Orca HCM from Learning Digital, affecting versions prior to 11.0. This vulnerability allows remote attackers with regular privileges to upload and execute web shells on the server.
Exploitation of this vulnerability could lead to unauthorized file uploads, allowing attackers to execute malicious scripts on the server via uploaded web shells.
Users are advised to update to Orca HCM version 11.0 or later. Customized users should contact the vendor for update instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.