VulnerabilityModified
CVE-2012-4020
MosP kintai kanri before 4.1.0 does not enforce privilege requirements, which allows remote authenticated users to read other users' information via unspecified vectors.
MEDIUM 4.0EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
MosP kintai kanri before 4.1.0 does not enforce privilege requirements, which allows remote authenticated users to read other users' information via unspecified vectors.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mosp/kintai kanri
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN23465354/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000096
- http://secunia.com/advisories/51110
- http://www.securityfocus.com/bid/56368
- http://jvn.jp/en/jp/JVN23465354/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2012-000096
- http://secunia.com/advisories/51110
- http://www.securityfocus.com/bid/56368
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.