CVE-2024-3775
- EPSS 0.41%
- Veröffentlicht 15.04.2024 04:15:16
- Zuletzt bearbeitet 08.04.2025 16:30:51
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
CVE-2024-3774
- EPSS 0.36%
- Veröffentlicht 15.04.2024 03:16:08
- Zuletzt bearbeitet 17.11.2025 18:53:09
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
CVE-2023-20853
- EPSS 0.99%
- Veröffentlicht 27.04.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:41:41
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitra...
CVE-2023-20852
- EPSS 0.99%
- Veröffentlicht 27.04.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:41:41
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operatio...
CVE-2022-39042
- EPSS 1.45%
- Veröffentlicht 03.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:26
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
CVE-2022-39041
- EPSS 1.24%
- Veröffentlicht 03.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:25
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
CVE-2022-39040
- EPSS 1.73%
- Veröffentlicht 03.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:25
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVE-2022-39039
- EPSS 1.02%
- Veröffentlicht 03.01.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:25
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system ...
CVE-2022-28742
- EPSS 0.62%
- Veröffentlicht 09.09.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:51
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to s...
CVE-2022-28741
- EPSS 0.86%
- Veröffentlicht 09.09.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:50
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x