aEnrich Technology a+HRD's functionality for downloading...
Moderate severity
Unreviewed
Published
Apr 15, 2024
to the GitHub Advisory Database
•
Updated Apr 15, 2024
Description
Published by the National Vulnerability Database
Apr 15, 2024
Published to the GitHub Advisory Database
Apr 15, 2024
Last updated
Apr 15, 2024
aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
References