Vulnerabilities > CVE-2020-5539 - Authorization Bypass Through User-Controlled Key vulnerability in Grandit
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |