Security Advisory
CVE-2022-39039
9.8
CRITICAL
Vulnerability Description
aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
Published Date
January 3, 2023
Official Source
NIST NVD Advisory