aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.
| Software | From | Fixed in |
|---|---|---|
| aenrich / a+hrd | 6.8 | 6.8.x |