9.8
CVE-2024-8584
- EPSS 0.83%
- Veröffentlicht 09.09.2024 03:15:09
- Zuletzt bearbeitet 17.02.2025 04:15:08
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Learningdigital ≫ Orca Hcm Version < 11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.83% | 0.74 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.