First published: Wed Dec 01 2021(Updated: )
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
Credit: twcert@cert.org.tw twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Ehrd | =8 | |
Sun Ehrd | =9 | |
=8 | ||
=9 |
Update Sunnet eHRD version to 10
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.