CVE-2022-28741: Path Traversal
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28741?
CVE-2022-28741 is classified as a high severity vulnerability due to its potential impact on the affected system.
How do I fix CVE-2022-28741?
To fix CVE-2022-28741, apply the latest security patch provided by AEnrich for the affected versions of the software.
What types of attacks can exploit CVE-2022-28741?
CVE-2022-28741 can be exploited through local file inclusion attacks, allowing attackers to read sensitive files on the server.
Which versions of aEnrich a+HRD are affected by CVE-2022-28741?
CVE-2022-28741 affects aEnrich a+HRD versions from 5.0 to 7.0, specifically versions 5.0 through 5.6 and all versions prior to 6.0.
What causes the CVE-2022-28741 vulnerability?
CVE-2022-28741 is caused by missing input validation in the aEnrich a+HRD Learning Management Key Performance Indicator System.