Lucene search

K
nvd[email protected]NVD:CVE-2022-28741
HistorySep 09, 2022 - 4:15 p.m.

CVE-2022-28741

2022-09-0916:15:08
CWE-22
web.nvd.nist.gov
2
enrich a+hrd
lfi
vulnerability
missing input validation

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.4%

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x

Affected configurations

Nvd
Node
aenricha\+hrdRange5.05.4.1125v112
OR
aenricha\+hrdRange5.55.5.1098v156
OR
aenricha\+hrdRange5.65.6.1067v110
OR
aenricha\+hrdRange6.07.0
VendorProductVersionCPE
aenricha\+hrd*cpe:2.3:a:aenrich:a\+hrd:*:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

59.4%

Related for NVD:CVE-2022-28741