← Back

CVE-2020-7874

nvd nist
Published: Sep 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.

Affected (1)

Products: Tobesoft: Nexacro
1 product
Nexacro
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 14.0.0.0 to 14.0.1.3600
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.