aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2022-04-07T18:22:42.703916Z

Updated: 2024-09-17T01:56:47.206Z

Reserved: 2022-03-08T00:00:00

Link: CVE-2022-26675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-07T19:15:09.060

Modified: 2022-04-14T19:00:02.410

Link: CVE-2022-26675

cve-icon Redhat

No data.