Aenrich

A+hrd

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 27.04.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:41:41

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitra...

  • EPSS 0.48%
  • Veröffentlicht 27.04.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:41:41

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operatio...

  • EPSS 0.08%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:26

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

  • EPSS 0.38%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • EPSS 0.09%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

  • EPSS 0.58%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system ...

  • EPSS 0.37%
  • Veröffentlicht 09.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:51

aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to s...

  • EPSS 0.58%
  • Veröffentlicht 09.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:50

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x

  • EPSS 0.32%
  • Veröffentlicht 09.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:50

aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.

  • EPSS 0.26%
  • Veröffentlicht 07.04.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:54:19

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.