aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://www.aenrich.com.tw | vendor advisory |
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0035/MNDT-2022-0035.md | third party advisory |