CVE-2020-5539
Summary
| CVE | CVE-2020-5539 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-02 08:15:00 UTC |
| Updated | 2020-03-04 19:56:00 UTC |
| Description | GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors. |
Risk And Classification
Problem Types: CWE-639
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Grandit | Grandit | 1.6 | All | All | All |
| Application | Grandit | Grandit | 2.0 | All | All | All |
| Application | Grandit | Grandit | 2.1 | All | All | All |
| Application | Grandit | Grandit | 2.2 | All | All | All |
| Application | Grandit | Grandit | 2.3 | All | All | All |
| Application | Grandit | Grandit | 3.0 | All | All | All |
| Application | Grandit | Grandit | 1.6 | All | All | All |
| Application | Grandit | Grandit | 2.0 | All | All | All |
| Application | Grandit | Grandit | 2.1 | All | All | All |
| Application | Grandit | Grandit | 2.2 | All | All | All |
| Application | Grandit | Grandit | 2.3 | All | All | All |
| Application | Grandit | Grandit | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.grandit.jp/etc/20200228_letter.pdf | MISC | www.grandit.jp | Vendor Advisory |
| JVN#73472345: GRANDIT vulnerable to session management | MISC | jvn.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.