Description
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Published: 2024-04-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to eHRD 6.8.1039V1055 or later version Update to eHRD 7.0.1141V422 or later version Update to eHRD 7.1.1033V429 or later version Update to eHRD 7.2.1061V36 or later version

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32347 aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
History

Tue, 08 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich
Aenrich a\+hrd
CPEs cpe:2.3:a:aenrich:a\+hrd:6.8:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.0:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.1:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.2:*:*:*:*:*:*:*
Vendors & Products Aenrich
Aenrich a\+hrd

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T20:20:01.574Z

Reserved: 2024-04-15T01:56:14.581Z

Link: CVE-2024-3775

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:01.574Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T04:15:16.137

Modified: 2025-04-08T16:30:51.500

Link: CVE-2024-3775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses