Vulnerabilities
Vulnerable Software
Aenrich:  Security Vulnerabilities
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application
CVSS Score
7.5
EPSS Score
0.006
Published
2022-09-09
aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
CVSS Score
7.5
EPSS Score
0.021
Published
2022-04-07
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
CVSS Score
9.8
EPSS Score
0.013
Published
2022-04-07


Contact Us

Shodan ® - All rights reserved