PT-2022-18004 · Unknown · Aenrich A+Hrd

Kun Xian Lin

·

Published

2022-04-07

·

Updated

2022-04-14

·

CVE-2022-26676

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aEnrich a+HRD (affected versions not specified)
Description The issue is related to inadequate privilege restrictions in aEnrich a+HRD, allowing an unauthenticated remote attacker to use an API function to upload and execute malicious scripts. This can lead to control of the system or disruption of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26676

Affected Products

Aenrich A+Hrd