Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2022-39040
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-39039
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
0
Attacker Value
Unknown
CVE-2022-28742
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application
0
Attacker Value
Unknown
CVE-2022-28741
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
0
Attacker Value
Unknown
CVE-2022-28740
Disclosure Date: September 09, 2022 (last updated October 08, 2023)
aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.
0
Attacker Value
Unknown
CVE-2022-26676
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
0
Attacker Value
Unknown
CVE-2022-26675
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
0