Hanvon E-Face is Hanvon Technology’s cloud-based interoperability platform built on a ten-million-level facial recognition algorithm. The platform’s imgDownload.do interface contains an arbitrary file-read vulnerability that allows attackers to read sensitive data and files from the server. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021. Other reference:None