Record summary

CVE-2020-15050 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBBio Star 2.8.2 - Local File InclusionExploitDB exploitby SITE TeamNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHSuprema BioStar <2.8.2 - Local File InclusionCVSS 7.5

Suprema BioStar before 2.8.2 Video Extension allows remote attackers can read arbitrary files from the server via local file inclusion.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the server.

Remediation

Upgrade Suprema BioStar to version 2.8.2 or later to fix the LFI vulnerability.

WeaknessesCWE-22
Authorsgy741
Template tagscvecve2020supremabiostar2packetstormlfisupremaincvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3