aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.
| Software | From | Fixed in |
|---|---|---|
| aenrich / a+hrd | 6.8 | 6.8.x |
| aenrich / a+hrd | 7.0 | 7.0.x |
| aenrich / a+hrd | 7.1 | 7.1.x |
| aenrich / a+hrd | 7.2 | 7.2.x |