Vulnerabilities
Vulnerable Software
Aenrich:  >> A+hrd  >> 7.0  Security Vulnerabilities
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
CVSS Score
7.5
EPSS Score
0.009
Published
2023-01-03
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
CVSS Score
9.8
EPSS Score
0.012
Published
2023-01-03
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-01-03


Contact Us

Shodan ® - All rights reserved