Vulnerabilities > CVE-2021-35965 - Insecure Default Initialization of Resource vulnerability in Learningdigital Orca HCM
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |