Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ehrd | Sun | 8 (including) | 8 (including) |
Ehrd | Sun | 9 (including) | 9 (including) |