aEnrich Technology a+HRD Insecure Deserialization Vulnerability Leading to Arbitrary Code Execution

Vulnerability

An insecure deserialization vulnerability has been identified in a+HRD by aEnrich Technology, affecting versions through 7.5. This vulnerability allows remote attackers with database modification privileges and standard system privileges to execute arbitrary code.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Remediation

Users are advised to upgrade to version 6.8 or later and install the latest patches. For assistance, contact aEnrich customer service.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
2.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.