4
CVSSv2

CVE-2020-14946

Published: 22/06/2020 Updated: 30/01/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 357
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and previous versions allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

globalradar bsa radar

Exploits

BSA Radar version 16723424750 suffers from a local file inclusion vulnerability ...

Github Repositories

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio

CVE submissions for the Global Radar - BSA Radar banking application

BSA Radar - CVE Submissions and Exploits The following vulnerabilities have been disclosed to the vendor and remediated in new versions of the BSA Radar application provided by GLOBAL Radar CVE-2020-14943 - Stored XSS CVE-2020-14944 - Access Control Vulnerabilities CVE-2020-14945 - Privilege Escalation CVE-2020-14946 - Local File Inclusion Affected versions: BSA Radar versio