ZeroHour

CVE-2022-26676

CVSS 3.1
9.8 critical
EPSS
1%p70
Published
()
Modified
Description

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.

Vendors
aenrich
Products
a\+hrd
Weakness
CWE-269, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.