Medium severity6.1NVD Advisory· Published Jul 19, 2021· Updated Jun 17, 2026
CVE-2021-35966
CVE-2021-35966
Description
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Learningdigital.com, Inc./Orca HCMv5Range: unspecified
Patches
Vulnerability mechanics
References
2- www.twcert.org.tw/tw/cp-132-4926-dc06b-1.htmlnvdThird Party Advisory
- www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25nvdNot Applicable
News mentions
0No linked articles in our index yet.