ZeroHour

CVE-2022-26675

CVSS 3.1
7.5 high
EPSS
2%p82
Published
()
Modified
Description

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.

Vendors
aenrich
Products
a\+hrd
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.