PT-2020-19333 · Visam · Visam Vbase Web-Remote Module+1

Published

2020-04-03

·

Updated

2020-04-06

·

CVE-2020-7008

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VISAM VBASE Editor version 11.5.0.2 VISAM VBASE Web-Remote Module
Description The issue allows input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
Recommendations For VISAM VBASE Editor version 11.5.0.2, consider restricting access to the URL parameter to minimize the risk of exploitation. For VISAM VBASE Web-Remote Module, avoid using unverified input from the URL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7008

Affected Products

Visam Vbase Editor
Visam Vbase Web-Remote Module