CVE-2020-14945
HIGHGlobal RADAR BSA Radar <1.6.7234.24750 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-14945. PoCs published by William Summerhill.
AI-analyzed exploit summary This exploit demonstrates an authenticated privilege escalation vulnerability in BSA Radar 1.6.7234.24750 and lower. By forging a request to the SaveUser endpoint, a low-privileged user can escalate their role to BankAdmin.
Description
A privilege escalation vulnerability exists within Global RADAR BSA Radar 1.6.7234.24750 and earlier that allows an authenticated, low-privileged user to escalate their privileges to administrator rights (i.e., the BankAdmin role) via modified SaveUser data.
Exploits (1)
This exploit demonstrates an authenticated privilege escalation vulnerability in BSA Radar 1.6.7234.24750 and lower. By forging a request to the SaveUser endpoint, a low-privileged user can escalate their role to BankAdmin.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H