vendor:
BSA Radar
by:
William Summerhill
4.3
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: BSA Radar
Affected Version From: BSA Radar - Version 1.6.7234.24750 and lower
Affected Version To: BSA Radar - Version 1.6.7234.24750 and lower
Patch Exists: YES
Related CWE: CVE-2020-14946
CPE: a:globalradar:bsa_radar
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
BSA Radar 1.6.7234.24750 – Local File Inclusion
The Administrator section of the Surveillance module in Global RADAR - BSA Radar 1.6.7234.X and lower allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files on the backend server.
Mitigation:
1. Upgrade to the latest version of BSA Radar. 2. Restrict access to the vulnerable endpoint. 3. Implement input validation and sanitization.