CVE-2020-14946

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/06/2020
Last modified:
30/01/2023

Description

downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:globalradar:bsa_radar:*:*:*:*:*:*:*:* 1.6.7234.24750 (including)