← Back

CVE-2022-28742

nvd nist
Published: Sep 9, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application

Affected (4)

Products: Aenrich: A+hrd
1 product
A+hrd
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Aenrich
From 5.0 to 5.4.1125v112
From 5.5 to 5.5.1098v156
From 5.6 to 5.6.1067v110
From 6.0 to 7.0

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.