Security Advisory

CVE-2020-14946

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-06-22 21:43:00
Last updated 2024-08-04 13:00:52
Assigner mitre
State PUBLISHED

Description

downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and earlier allows users to download transaction files. When downloading the files, a user is able to view local files on the web server by manipulating the FileName and FilePath parameters in the URL, or while using a proxy. This vulnerability could be used to view local sensitive files or configuration files.