peter bassill · operator
$ cve CVE-2020-14946 JSON

CVE-2020-14946 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 7.7% (pctl 94)

Patch early

A public exploit exists.

Description

downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS7.7% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2020-06-22
Last modified2026-06-17

Affected (1)

VendorProduct
globalradarbsa radar

Public exploits

SourceTitleDate
exploit-dbBSA Radar 1.6.7234.24750 - Local File Inclusion2020-07-14

References

→ the Explorer  ·  watch your stack  ·  NVD