Sunnet eHRD has broken access control vulnerability,...
High severity
Unreviewed
Published
Dec 2, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Dec 1, 2021
Published to the GitHub Advisory Database
Dec 2, 2021
Last updated
Jan 27, 2023
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
References