There is a directory traversing vulnerability in the download page url of AquaNPlayer The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause information leakage.

Source: CVE-2020-7858

