Vulnerabilities > CVE-2021-35965 - Insecure Default Initialization of Resource vulnerability in Learningdigital Orca HCM
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |