Aenrich

A+hrd

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 15.04.2024 04:15:16
  • Zuletzt bearbeitet 08.04.2025 16:30:51

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.

  • EPSS 0.36%
  • Veröffentlicht 15.04.2024 03:16:08
  • Zuletzt bearbeitet 17.11.2025 18:53:09

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.

  • EPSS 0.99%
  • Veröffentlicht 27.04.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:41:41

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitra...

  • EPSS 0.99%
  • Veröffentlicht 27.04.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:41:41

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operatio...

  • EPSS 1.45%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:26

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

  • EPSS 1.24%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • EPSS 1.73%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

  • EPSS 1.02%
  • Veröffentlicht 03.01.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 07:17:25

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system ...

  • EPSS 0.62%
  • Veröffentlicht 09.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:51

aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to s...

  • EPSS 0.86%
  • Veröffentlicht 09.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:57:50

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x