CVE-2022-26676: aEnrich a+HRD - Broken Access Control
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-26676?
CVE-2022-26676 is a vulnerability in aEnrich a+HRD that allows an unauthenticated remote attacker to upload and execute malicious scripts to control the system or disrupt service.
What is the severity of CVE-2022-26676?
CVE-2022-26676 has a severity rating of 9.8, which is considered critical.
How does CVE-2022-26676 affect aEnrich a+HRD?
CVE-2022-26676 affects aEnrich a+HRD by exposing a vulnerability that allows an unauthenticated remote attacker to upload and execute malicious scripts.
How can an attacker exploit CVE-2022-26676?
An attacker can exploit CVE-2022-26676 by using the API function to upload and execute malicious scripts on the vulnerable system.
Is there a fix available for CVE-2022-26676?
Currently, there is no information available regarding a fix for CVE-2022-26676. It is recommended to follow the guidelines provided by the vendor or the security advisories for updates.