CVE-2024-3775
EUVD-2024-3234715.04.2024, 04:15
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| aenrich | a\+hrd | 6.8 |
| aenrich | a\+hrd | 7.0 |
| aenrich | a\+hrd | 7.1 |
| aenrich | a\+hrd | 7.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| aenrich | a\+hrd | 6.8 ≤ 𝑥 < 6.8.1039V1055 | ADP |
| aenrich | a\+hrd | 7.0 ≤ 𝑥 < 7.0.1141V422 | ADP |
| aenrich | a\+hrd | 7.1 ≤ 𝑥 < 7.1.1033V429 | ADP |
| aenrich | a\+hrd | 7.2 ≤ 𝑥 < 7.2.1061V36 | ADP |