Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2023-20853
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2023-20852
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2022-39042
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
0
Attacker Value
Unknown
CVE-2022-39041
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
0
Attacker Value
Unknown
CVE-2022-39040
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-39039
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
0
Attacker Value
Unknown
CVE-2022-26676
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
0
Attacker Value
Unknown
CVE-2022-26675
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
0