aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.
| Software | From | Fixed in |
|---|---|---|
| aenrich / a+hrd | 6.8 | 6.8.x |
| aenrich / a+hrd | 7.0 | 7.0.x |