Front-end Retrieval of System Configuration Values Vulnerability
CVE-2024-3774
5.3MEDIUM
What is CVE-2024-3774?
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
Affected Version(s)
a+HRD 6.8
a+HRD 7.0
a+HRD 7.1
