aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
| Software | From | Fixed in |
|---|---|---|
| aenrich / a+hrd | 6.8 | 6.8.x |
| aenrich / a+hrd | 7.0 | 7.0.x |