Arbitrary File Download Vulnerability in a+HRD
CVE-2024-3775
7.5HIGH
What is CVE-2024-3775?
The a+HRD application from aEnrich Technology contains an improper input validation vulnerability affecting its file downloading functionality. This flaw allows attackers to exploit the system by manipulating user input to pass arbitrary arguments to youtube-dl.exe, potentially enabling the download of unauthorized files. Users are advised to restrict input validation to prevent unauthorized file access.
Affected Version(s)
a+HRD 6.8
a+HRD 7.0
a+HRD 7.1
