A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to download any file. The attacker is able to use startup menu directory via directory traversal for automatic execution. The victim user need to reboot, however.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: krcert
Published: 2020-08-24T15:00:55.627299Z
Updated: 2024-09-17T02:12:07.149Z
Reserved: 2020-01-22T00:00:00
Link: CVE-2020-7831
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-08-24T15:15:14.160
Modified: 2024-11-21T05:37:53.360
Link: CVE-2020-7831
Redhat
No data.