Description
Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
No analysis available yet.
Remediation
Vendor Solution
Update Sunnet eHRD version to 10
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30294 | Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T18:43:15.405Z
Reserved: 2021-11-04T00:00:00.000Z
Link: CVE-2021-43359
No data.
Status : Modified
Published: 2021-12-01T02:15:07.343
Modified: 2024-11-21T06:29:07.600
Link: CVE-2021-43359
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD