CVE-2020-14946
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files.
Does this matter?
Lower severity and a low EPSS score (7.70%). Track it; it rarely justifies an emergency change on its own.
Description
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 7.70% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- globalradar/bsa radar
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/158420/BSA-Radar-1.6.7234.24750-Local-File-Inclusion.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/wsummerhill/BSA-Radar_CVE-VulnerabilitiesThird Party Advisory
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-2020-14946%20-%20Local%20File%20Inclusion.mdExploit, Third Party Advisory
- http://packetstormsecurity.com/files/158420/BSA-Radar-1.6.7234.24750-Local-File-Inclusion.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/wsummerhill/BSA-Radar_CVE-VulnerabilitiesThird Party Advisory
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-2020-14946%20-%20Local%20File%20Inclusion.mdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.