9.8
CVSSv3

CVE-2022-39039

Published: 03/01/2023 Updated: 10/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

Vulnerable Product Search on Vulmon Subscribe to Product

aenrich a\\+hrd 6.8

aenrich a\\+hrd 7.0