CVE-2020-7830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/09/2020
Last modified:
11/09/2020

Description

RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths. This issue affects: RAONWIZ RAON KUpload 2018.0.2.50 versions and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:raonwiz:raon_kupload:*:*:*:*:*:*:*:* 2018.0.2.50 (including)