Description
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
Problem types
CWE-306 Missing Authentication for Critical Function
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
6.8
7.0 (custom)
References
www.twcert.org.tw/tw/cp-132-7724-c28d3-1.html
www.twcert.org.tw/tw/cp-132-7724-c28d3-1.html