CVE-2025-0202

MEDIUM

TCS BaNCS 10 - File Inclusion

Title source: llm
STIX 2.1

Description

A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the file /REPORTS/REPORTS_SHOW_FILE.jsp. The manipulation of the argument FilePath leads to file inclusion. The real existence of this vulnerability is still doubted at the moment.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-73
Status published
Products (1)
TCS/BaNCS 10
Published Jan 04, 2025
Tracked Since Feb 18, 2026