CVE-2020-7814: Input Validation
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in COMPONENT of RAONWIZ RAON KUpload allows ATTACKER/ATTACK to cause IMPACT. This issue affects: RAONWIZ RAON KUpload 2018.0.2.50 versions prior to 2018.0.2.51 on Windows.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7814?
CVE-2020-7814 is a vulnerability in RAONWIZ v2018.0.2.50 and earlier versions that allows remote files to be downloaded and executed by lack of validation to file extension.
What is the severity of CVE-2020-7814?
The severity of CVE-2020-7814 is critical with a CVSS score of 9.8.
Which component of RAONWIZ is affected by CVE-2020-7814?
The vulnerability affects the ____COMPONENT____ of RAONWIZ RAO.
How can hackers exploit CVE-2020-7814?
Hackers can exploit CVE-2020-7814 by using it as a remote code execution vulnerability, enabling them to download and execute remote files.
Is Microsoft Windows affected by CVE-2020-7814?
No, Microsoft Windows is not affected by CVE-2020-7814.
Is there a fix available for CVE-2020-7814?
Currently, there is no available fix for CVE-2020-7814. It is recommended to update to a patched version if one becomes available.