Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-7831


A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to download any file. The attacker is able to use startup menu directory via directory traversal for automatic execution. The victim user need to reboot, however.


Published

2020-08-24T15:15:14.160

Last Modified

2024-11-21T05:37:53.360

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-494
  • Type: Primary
    CWE-494

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application inogard ebiz4u cviewer_object_1.0.5.1 Yes
Operating System microsoft windows - No

References