The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
The vulnerability classified as CWE-1390 (Weak Authentication) involves a flawed authentication mechanism in the a+HRD application. An unauthorized attacker can send specially crafted network packets to the system, which result in the server returning a valid administrator access token. The obtained token can then be used to log in and perform operations with the highest privilege level in the application.
An attacker gains full administrative access to the a+HRD system, enabling them to read, modify, or delete personnel and HR data stored in the system. It is also possible to further seize control over organizational resources accessible from the compromised application level.
Apply patches available from the vendor in accordance with the references — detailed information on patched software versions is available in the TWCERT bulletin (https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html) and in the CHT Security security advisory. Until updates are deployed, it is recommended to restrict application access at the network level (firewall) to trusted IP addresses only.
The a+HRD system developed by aEnrich (aEnrich Technology); specific vulnerable versions are indicated in the vendor references and in the TWCERT bulletin.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAenrich A\+hrd
APPAenrich≤ 7.5
Related vulnerabilities
Aenrich A+HRD – obejście uwierzytelnienia przez fałszywe tokeny administratora
SQL Injection w Aenrich A+HRD — nieuwierzytelniony zdalny dostęp do bazy danych
Deserializacja niezaufanych danych w aEnrich a+HRD — RCE bez uwierzytelnienia
Deserializacja niezaufanych danych w aEnrich a+HRD (MSMQ) — RCE bez uwierzytelnienia
SQL Injection w aEnrich a+HRD — nieuwierzytelniony dostęp do bazy danych