CVE-2020-7830

HIGH

RAONWIZ v2018.0.2.50- - Info Disclosure

Title source: llm
STIX 2.1

Description

RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths. This issue affects: RAONWIZ RAON KUpload 2018.0.2.50 versions and earlier.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0080
EPSS Percentile 52.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
raonwiz/raon_kupload < 2018.0.2.50
Published Sep 02, 2020
Tracked Since Feb 18, 2026