The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.
Solution:
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-8164-fe7c5-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-8165-7da2f-2.html | third party advisory |