Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-39042
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
0
Attacker Value
Unknown
CVE-2022-39041
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
0
Attacker Value
Unknown
CVE-2022-39040
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-39039
Disclosure Date: December 14, 2022 (last updated February 24, 2025)
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
0