aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6795-f7fe6-1.html |
|
History
Thu, 10 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published: 2023-01-03T00:00:00.000Z
Updated: 2025-04-10T15:49:09.860Z
Reserved: 2022-08-30T00:00:00.000Z
Link: CVE-2022-39042
Updated: 2024-08-03T11:10:32.451Z
Status : Modified
Published: 2023-01-03T03:15:09.877
Modified: 2024-11-21T07:17:26.100
Link: CVE-2022-39042
No data.