COVID Tracking System 1.0 SQL Injection

HIGH (7.3) No Patch

Threat Intelligence

Low Risk
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The COVID Tracking System is a web-based application used to track and manage COVID-19 data. The vulnerability discovered in version 1.0 allows an attacker to inject malicious SQL code into the system, potentially leading to unauthorized access to sensitive data.

Am I affected?

You're affected if you use A security vulnerability. Specific version info not stated in the advisory. If you don't recognise this software, you're probably not affected.

Affected Products

aEnrich / a+HRD

How to fix

Contact aEnrich directly for a patched version - there's no public patch link in the advisory.
Immediate mitigations:
- Restrict network access to your a+HRD instance (firewall it from the public internet)
- Audit admin account activity for suspicious access patterns
- Monitor for unauthorized token creation