GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2020-03-02T07:00:24

Updated: 2020-03-02T07:00:24

Reserved: 2020-01-06T00:00:00


Link: CVE-2020-5539

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-03-02T08:15:10.660

Modified: 2020-03-04T19:56:03.603


Link: CVE-2020-5539

JSON object: View

cve-icon Redhat Information

No data.

CWE