9.8
CVSSv3

CVE-2020-14944

Published: 22/06/2020 Updated: 03/05/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Global RADAR BSA Radar 1.6.7234.24750 and previous versions lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

globalradar bsa radar

Exploits

BSA Radar version 16723424750 suffers from a persistent cross site scripting vulnerability ...
BSA Radar version 16723424750 suffers from a cross site request forgery vulnerability ...

Github Repositories

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio