CVE-2024-3775
15.04.2024, 04:15
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Vendor | Product | Version |
---|---|---|
aenrich | a\+hrd | 6.8 |
aenrich | a\+hrd | 7.0 |
aenrich | a\+hrd | 7.1 |
aenrich | a\+hrd | 7.2 |
𝑥
= Vulnerable software versions