aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-31225 | aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory. |
Fixes
Solution
Update version to eHRD6.8.1039V768
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5969-a5d4a-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T01:56:47.206Z
Reserved: 2022-03-08T00:00:00
Link: CVE-2022-26675
No data.
Status : Modified
Published: 2022-04-07T19:15:09.060
Modified: 2024-11-21T06:54:19.127
Link: CVE-2022-26675
No data.
OpenCVE Enrichment
No data.
EUVD