CVE-2024-8585

Publication date

2024-09-09 03:03:59

Family

twcert

State

PUBLISHED

Description

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.