VulnerabilityModified
CVE-2020-5539
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.
MEDIUM 6.5EPSS 0.84%
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- grandit/grandit
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN73472345/index.htmlThird Party Advisory
- https://www.grandit.jp/etc/20200228_letter.pdfVendor Advisory
- https://jvn.jp/en/jp/JVN73472345/index.htmlThird Party Advisory
- https://www.grandit.jp/etc/20200228_letter.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.