The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Please refer to the aEnrich advisory to upgrade to version 6.8 or later and install the latest patches, or contact aEnrich customer service for assistance.


Workaround

No workaround given by the vendor.

History

Wed, 22 Apr 2026 04:00:00 +0000

Type Values Removed Values Added
Description The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
Title aEnrich|a+HCM - Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-04-22T03:40:36.559Z

Reserved: 2026-04-22T02:48:35.815Z

Link: CVE-2026-6835

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-22T04:16:09.560

Modified: 2026-04-22T04:16:09.560

Link: CVE-2026-6835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T06:15:10Z

Weaknesses