Description
The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which will execute on the client side when a user is tricked into visiting a specific URL.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version
8.1 (custom)
References
www.twcert.org.tw/tw/cp-132-10486-a3459-1.html
www.twcert.org.tw/en/cp-139-10487-12a32-2.html