Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2025-0586

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.
Attacker Value
Unknown

CVE-2025-0585

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Attacker Value
Unknown

CVE-2025-0584

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
Attacker Value
Unknown

CVE-2025-0583

Disclosure Date: January 20, 2025 (last updated January 20, 2025)
The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Attacker Value
Unknown

CVE-2024-3775

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
0
Attacker Value
Unknown

CVE-2024-3774

Disclosure Date: April 15, 2024 (last updated January 05, 2025)
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
0
Attacker Value
Unknown

CVE-2023-20853

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2023-20852

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2022-39042

Disclosure Date: December 14, 2022 (last updated October 08, 2023)
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
Attacker Value
Unknown

CVE-2022-39041

Disclosure Date: December 14, 2022 (last updated October 08, 2023)
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.