CVE-2022-26675

HIGH

aEnrich a+HRD - Unauthenticated Path Traversal via URL Special Character Bypass

Title source: llm
STIX 2.1

Description

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-5969-a5d4a-1.html

Scores

CVSS v3 7.5
EPSS 0.0213
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
aenrich/a\+hrd 6.8
Published Apr 07, 2022
Tracked Since Feb 18, 2026