CVE-2020-14944 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 6.3% (pctl 93)
Patch early
A public exploit exists.
Description
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.34% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-862 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-06-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| globalradar | bsa radar |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password) | 2020-07-08 |
References
- http://packetstormsecurity.com/files/158372/BSA-Radar-1.6.7234.24750-Cross-Site-Request-Forgery.html
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-2020-14944%20-%20Access%20Control%20Vulnerabilities.md
- http://packetstormsecurity.com/files/158372/BSA-Radar-1.6.7234.24750-Cross-Site-Request-Forgery.html
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities
- https://github.com/wsummerhill/BSA-Radar_CVE-Vulnerabilities/blob/master/CVE-2020-14944%20-%20Access%20Control%20Vulnerabilities.md
→ the Explorer · watch your stack · NVD