Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NCRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version
affected
Description
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
Problem types
Product status
Any version
References
www.chtsecurity.com/.../b97e8337-6b0c-43e8-8e8c-187b7c0e13c2
www.twcert.org.tw/tw/cp-132-10486-a3459-1.html
www.twcert.org.tw/en/cp-139-10487-12a32-2.html