aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32347 | aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files. |
Fixes
Solution
Update to eHRD 6.8.1039V1055 or later version Update to eHRD 7.0.1141V422 or later version Update to eHRD 7.1.1033V429 or later version Update to eHRD 7.2.1061V36 or later version
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7726-e5f70-1.html |
|
History
Tue, 08 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aenrich
Aenrich a\+hrd |
|
| CPEs | cpe:2.3:a:aenrich:a\+hrd:6.8:*:*:*:*:*:*:* cpe:2.3:a:aenrich:a\+hrd:7.0:*:*:*:*:*:*:* cpe:2.3:a:aenrich:a\+hrd:7.1:*:*:*:*:*:*:* cpe:2.3:a:aenrich:a\+hrd:7.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Aenrich
Aenrich a\+hrd |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T20:20:01.574Z
Reserved: 2024-04-15T01:56:14.581Z
Link: CVE-2024-3775
Updated: 2024-08-01T20:20:01.574Z
Status : Analyzed
Published: 2024-04-15T04:15:16.137
Modified: 2025-04-08T16:30:51.500
Link: CVE-2024-3775
No data.
OpenCVE Enrichment
No data.
EUVD