Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LEARNING DIGITAL Orca HCM - Arbitrary File Download
Vulnerability Description
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
LearningDigital Orca HCM 路径遍历漏洞
Vulnerability Description
LearningDigital Orca HCM是中国一宇数位(LearningDigital)公司的一个数字学习平台。 LearningDigital Orca HCM 11.0之前版本存在路径遍历漏洞,该漏洞源于未正确限制文件下载功能的特定参数,从而允许具有常规权限的远程攻击者下载任意系统文件。
CVSS Information
N/A
Vulnerability Type
N/A