Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
https://www.twcert.org.tw/tw/cp-132-8039-24e48-1.html
https://www.twcert.org.tw/en/cp-139-8040-948ef-2.html
Source: Mitre, NVD
Published: 2024-09-09
Updated: 2025-02-17
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00629