Vulnerabilities > Aenrich

DATE CVE VULNERABILITY TITLE RISK
2023-04-27 CVE-2023-20852 Deserialization of Untrusted Data vulnerability in Aenrich A+Hrd 6.8.1039V844
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter.
network
low complexity
aenrich CWE-502
critical
9.8
2023-04-27 CVE-2023-20853 Deserialization of Untrusted Data vulnerability in Aenrich A+Hrd 6.8.1039V844
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process.
network
low complexity
aenrich CWE-502
critical
9.8
2023-01-03 CVE-2022-39039 Server-Side Request Forgery (SSRF) vulnerability in Aenrich A+Hrd 6.8/7.0
aEnrich’s a+HRD has inadequate filtering for specific URL parameter.
network
low complexity
aenrich CWE-918
critical
9.8
2023-01-03 CVE-2022-39040 Path Traversal vulnerability in Aenrich A+Hrd 6.8/7.0
aEnrich a+HRD log read function has a path traversal vulnerability.
network
low complexity
aenrich CWE-22
7.5
2023-01-03 CVE-2022-39041 SQL Injection vulnerability in Aenrich A+Hrd 6.8/7.0
aEnrich a+HRD has insufficient user input validation for specific API parameter.
network
low complexity
aenrich CWE-89
critical
9.8
2023-01-03 CVE-2022-39042 Improper Authentication vulnerability in Aenrich A+Hrd 6.8/7.0
aEnrich a+HRD has improper validation for login function.
network
low complexity
aenrich CWE-287
critical
9.8
2022-09-09 CVE-2022-28740 Unspecified vulnerability in Aenrich A+Hrd
aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.
network
low complexity
aenrich
7.5
2022-09-09 CVE-2022-28741 Path Traversal vulnerability in Aenrich A+Hrd
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
network
high complexity
aenrich CWE-22
8.1
2022-09-09 CVE-2022-28742 Unspecified vulnerability in Aenrich A+Hrd
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control.
network
low complexity
aenrich
7.5
2022-04-07 CVE-2022-26675 Path Traversal vulnerability in Aenrich A+Hrd 6.8
aEnrich a+HRD has inadequate filtering for special characters in URLs.
network
low complexity
aenrich CWE-22
7.5