CVE-2020-14944
Summary
| CVE | CVE-2020-14944 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-22 22:15:00 UTC |
| Updated | 2022-05-03 13:59:00 UTC |
| Description | Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Globalradar | Bsa Radar | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - wsummerhill/BSA-Radar_CVE-Vulnerabilities: CVE submissions for the Global Radar - BSA Radar banking application | MISC | github.com | Third Party Advisory |
| BSA-Radar_CVE-Vulnerabilities/CVE-2020-14944 - Access Control Vulnerabilities.md at master · wsummerhill/BSA-Radar_CVE-Vulnerabilities · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| BSA Radar 1.6.7234.24750 Cross Site Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.