CVE-2024-3774: Aenrich A+hrd

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.

Affected products

  • Aenrich A+hrd: version 6.8 only; version 7.0 only; version 7.1 only; version 7.2 only

Published 2024-04-15. Last modified 2026-06-17.