CVE-2024-3774: aEnrich Technology a+HRD - Exposure of Sensitive Data
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3774?
CVE-2024-3774 has a critical severity rating due to the potential for unauthorized access to sensitive system configuration values.
How do I fix CVE-2024-3774?
To fix CVE-2024-3774, implement proper input validation and parameter restrictions in the affected aEnrich A+HRD versions.
Which aEnrich A+HRD versions are affected by CVE-2024-3774?
CVE-2024-3774 affects aEnrich A+HRD versions 6.8, 7.0, 7.1, and 7.2.
What type of vulnerability is CVE-2024-3774?
CVE-2024-3774 is an access control vulnerability that allows attackers to read sensitive configuration data.
Can CVE-2024-3774 be exploited remotely?
Yes, CVE-2024-3774 can be exploited remotely if the system is not properly secured.