Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2025-0586

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.
Attacker Value
Unknown

CVE-2025-0585

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Attacker Value
Unknown

CVE-2025-0584

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
Attacker Value
Unknown

CVE-2025-0583

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Attacker Value
Unknown

CVE-2024-3775

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
0
Attacker Value
Unknown

CVE-2024-3774

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
0