CVE-2020-7808
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H
- EPSS probability
- 0.24%
- CWE
- CWE-353, CWE-88
- Published
- 2020-05-21
- Last modified
- 2026-03-14
Affected products
- RAONWIZ Inc K Upload
Weakness type
Related vulnerabilities
- CVE-2021-26608 — handysoft groupware arbitrary file download and execution vulnerability
- CVE-2020-7810 — HandySoft ActiveX File Download and Execution Vulnerability
- CVE-2020-10266 — RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot
- CVE-2019-11480 — Ubuntu kernel snap build process could use unauthenticated sources
- CVE-2021-28545 — Acrobat Reader DC Missing Support for Integrity Check
- CVE-2019-12804 — Hunesion i-oneNet Missing Support for Integrity Check vulnerability
- CVE-2023-32475 — Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system c
- CVE-2025-48500 — BIG-IP APM VPN web client for macOS vulnerability