go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

aEnrich Technology a+HRD - Argument Injection

TVN ID TVN-202404002
CVE ID CVE-2024-3775
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products aEnrich Technology a+HRD 6.8, 7.0, 7.1, 7.2
Description aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Solution Update to eHRD 6.8.1039V1055 or later version
Update to eHRD 7.0.1141V422 or later version
Update to eHRD 7.1.1033V429 or later version
Update to eHRD 7.2.1061V36 or later version
Credit Cyku(DEVCORE)
Public Date 2024-04-15
Top