ZeroHour

CVE-2022-39041

CVSS 3.1
9.8 critical
EPSS
1%p67
Published
()
Modified
Description

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

Vendors
aenrich
Products
a\+hrd
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.