The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
The vulnerability results from a flawed mechanism for generating or verifying administrative access tokens in the A+HRD application. An attacker can remotely, without possessing any credentials, independently construct (craft) a properly formatted administrator access token. The token prepared in this way is accepted by the system, resulting in obtaining full administrative privileges without going through the proper authentication process.
An attacker gains unauthorized access to the system with administrator privileges, enabling the reading, modification or deletion of sensitive personnel and payroll data, as well as further actions in the victim's environment.
Apply patches available from the vendor in accordance with the references (TWCERT: https://www.twcert.org.tw/en/cp-139-10487-12a32-2.html). Until the fix is implemented, it is recommended to restrict access to the A+HRD system only to trusted IP addresses through a firewall or VPN.
A+HRD system developed by aEnrich; specific versions indicated in the vendor's references.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAenrich A\+hrd
APPAenrich≤ 7.5
Related vulnerabilities
Authentication Abuse w aEnrich a+HRD — przejęcie tokenu administratora
SQL Injection w Aenrich A+HRD — nieuwierzytelniony zdalny dostęp do bazy danych
Deserializacja niezaufanych danych w aEnrich a+HRD — RCE bez uwierzytelnienia
Deserializacja niezaufanych danych w aEnrich a+HRD (MSMQ) — RCE bez uwierzytelnienia
SQL Injection w aEnrich a+HRD — nieuwierzytelniony dostęp do bazy danych