CRITICAL🇵🇱 Wersja polska

CVE-2025-12871

CVSS 9.3v4.0pub. 2025-11-12upd. 2025-11-18

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.

🤖 AI Analysis
How it works

The vulnerability results from a flawed mechanism for generating or verifying administrative access tokens in the A+HRD application. An attacker can remotely, without possessing any credentials, independently construct (craft) a properly formatted administrator access token. The token prepared in this way is accepted by the system, resulting in obtaining full administrative privileges without going through the proper authentication process.

Impact

An attacker gains unauthorized access to the system with administrator privileges, enabling the reading, modification or deletion of sensitive personnel and payroll data, as well as further actions in the victim's environment.

Mitigation & patch

Apply patches available from the vendor in accordance with the references (TWCERT: https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html). Until the fix is implemented, it is recommended to restrict access to the A+HRD system only to trusted IP addresses through a firewall or VPN.

Who is affected

A+HRD system developed by aEnrich; specific versions indicated in the vendor's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Aenrich A\+hrd

    APP
    Aenrich
    ≤ 7.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-12870CRITICAL9.3PL ✓same product

Authentication Abuse w aEnrich a+HRD — przejęcie tokenu administratora

CVE-2025-0585CRITICAL9.8PL ✓same product

SQL Injection w Aenrich A+HRD — nieuwierzytelniony zdalny dostęp do bazy danych

CVE-2023-20852CRITICAL9.8PL ✓same product

Deserializacja niezaufanych danych w aEnrich a+HRD — RCE bez uwierzytelnienia

CVE-2023-20853CRITICAL9.8PL ✓same product

Deserializacja niezaufanych danych w aEnrich a+HRD (MSMQ) — RCE bez uwierzytelnienia

CVE-2022-39041CRITICAL9.8PL ✓same product

SQL Injection w aEnrich a+HRD — nieuwierzytelniony dostęp do bazy danych