aEnrich a+HRD - Server-Side Request Forgery (SSRF)
CVE-2022-39039
9.8CRITICAL
What is CVE-2022-39039?
The aEnrich a+HRD product has a vulnerability due to inadequate filtering of specific URL parameters. This weakness allows an unauthenticated remote attacker to exploit it and send arbitrary HTTP or HTTPS requests. Such an exploit can lead to Server-Side Request Forgery (SSRF) attacks, enabling attackers to perform unauthorized system commands or disrupt services.
Affected Version(s)
a+HRD 6.8 <= 7.0
