PT-2020-19333 · Visam · Visam Vbase Web-Remote Module+1
Published
2020-04-03
·
Updated
2020-04-06
·
CVE-2020-7008
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VISAM VBASE Editor version 11.5.0.2
VISAM VBASE Web-Remote Module
Description
The issue allows input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
Recommendations
For VISAM VBASE Editor version 11.5.0.2, consider restricting access to the URL parameter to minimize the risk of exploitation.
For VISAM VBASE Web-Remote Module, avoid using unverified input from the URL until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Visam Vbase Editor
Visam Vbase Web-Remote Module