← Back to browse · API

CVE-2021-35965

Severity
CRITICAL
CVSS
9.8
EPSS
0.02378
Risk score
40.03
CISA KEV
No
PoC
No
Published
2021-07-19
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-22598, GHSA-W3WG-762H-Q86R
Products
LEARNING DIGITAL:Orca HCM unspecified ≤10.0
Sources
euvd EUVD-2021-22598

Description

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

References