Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
Solution:
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-8039-24e48-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-8040-948ef-2.html | third party advisory |