CVE-2022-28742: High severity aenrich vulnerability
aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28742?
CVE-2022-28742 has been classified as a high severity vulnerability due to improper access control allowing unauthorized access to sensitive functionalities.
How do I fix CVE-2022-28742?
To fix CVE-2022-28742, ensure that proper session validation is implemented for user authentication across all application pages.
Which versions of aEnrich eHRD Learning Management are affected by CVE-2022-28742?
CVE-2022-28742 affects aEnrich eHRD Learning Management versions between 5.0 and 5.4.1125v112, as well as 5.5, 5.6, and up to version 6.0, not including 7.0.
What can an attacker do by exploiting CVE-2022-28742?
By exploiting CVE-2022-28742, an attacker can gain unauthenticated access to sensitive functionalities within the application.
Is user session validation necessary in web applications like aEnrich eHRD?
Yes, user session validation is critical in web applications like aEnrich eHRD to prevent unauthorized access and ensure secure user interactions.