a+HRD Missing Authorization Vulnerability Allowing Arbitrary Database Read

Vulnerability

A missing authorization vulnerability has been identified in a+HRD developed by aEnrich, affecting versions through 7.1. This vulnerability allows authenticated remote attackers to read arbitrary database contents via a specific API method.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive database information.

Remediation

Users are advised to upgrade to version 6.8 or later and install the latest patches. For assistance, contact aEnrich customer service.

Added: Apr 22, 2026, 4:17 AM
Updated: Apr 22, 2026, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
7.7
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.