CVE-2022-39039

Publication date

2023-01-03 00:00:00

Family

twcert

State

PUBLISHED

Description

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.