CVE-2020-5616
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01]…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.06% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- calendar01 project/calendar01 · calendar02 project/calendar02 · calendarform01 project/calendarform01 · gallery01 project/gallery01 · link01 project/link01 · pkobo-news01 project/pkobo-news01 · pkobo-vote01 project/pkobo-vote01 · telop01 project/telop01
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN73169744/index.htmlThird Party Advisory
- https://www.php-factory.net/calendar/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/calendar/02.phpProduct, Third Party Advisory
- https://www.php-factory.net/calendar_form/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/gallery/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/link/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/news/pkobo-news01.phpProduct, Third Party Advisory
- https://www.php-factory.net/telop/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/vote/01.phpProduct, Third Party Advisory
- https://jvn.jp/en/jp/JVN73169744/index.htmlThird Party Advisory
- https://www.php-factory.net/calendar/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/calendar/02.phpProduct, Third Party Advisory
- https://www.php-factory.net/calendar_form/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/gallery/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/link/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/news/pkobo-news01.phpProduct, Third Party Advisory
- https://www.php-factory.net/telop/01.phpProduct, Third Party Advisory
- https://www.php-factory.net/vote/01.phpProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.