Vulnerability Description
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Globalradar | Bsa Radar | <= 1.6.7234.24750 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158420/BSA-Radar-1.6.7234.24750-Local-File-ExploitThird Party AdvisoryVDB Entry
- https://github.com/wsummerhill/BSA-Radar_CVE-VulnerabilitiesThird Party Advisory
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-202ExploitThird Party Advisory
- http://packetstormsecurity.com/files/158420/BSA-Radar-1.6.7234.24750-Local-File-ExploitThird Party AdvisoryVDB Entry
- https://github.com/wsummerhill/BSA-Radar_CVE-VulnerabilitiesThird Party Advisory
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-202ExploitThird Party Advisory
FAQ
What is CVE-2020-14946?
CVE-2020-14946 is a vulnerability with a CVSS score of 4.3 (MEDIUM). downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a...
How severe is CVE-2020-14946?
CVE-2020-14946 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14946?
Check the references section above for vendor advisories and patch information. Affected products include: Globalradar Bsa Radar.