go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

aEnrich|a+HRD - 2 Vulnerabilities

TVN ID TVN-202604004
CVE ID CVE-2026-6833, CVE-2026-6834
CVSS 【CVE-2026-6833】
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

【CVE-2026-6834】
6.5 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products a+HRD version 7.1 and earlier
Description 【CVE-2026-6833(SQL Injection)】
Authenticated remote attackers can inject arbitrary SQL commands to read database contents.

【CVE-2026-6834(Missing Authorization)】
Authenticated remote attackers can read arbitrary database contents through a specific API method.
Solution Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.
Credit Cyku Hong(DEVCORE)
Public Date 2026-04-17
Top