CVE-2024-3774: Aenrich A+hrd
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
Affected products
- Aenrich A+hrd: version 6.8 only; version 7.0 only; version 7.1 only; version 7.2 only
Published 2024-04-15. Last modified 2026-06-17.