« Volver al listado

CVE-2020-5616

Estado: ModificadaCrítica (9.8)—

[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5616",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "PHP Factory",
          "product": "[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01]",
          "versions": [
            {
              "status": "affected",
              "version": "[Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-04T02:15:11.657",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN73169744/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/calendar/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/calendar/02.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/calendar_form/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/gallery/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/link/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/news/pkobo-news01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/telop/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.php-factory.net/vote/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN73169744/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/calendar/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/calendar/02.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/calendar_form/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/gallery/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/link/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/news/pkobo-news01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/telop/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php-factory.net/vote/01.php",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01] y [Link01] [Calendar01] edición gratuita versión 1.0.0, [Calendar02] edición gratuita versión 1.0.0, [PKOBO-News01] edición gratuita versiones 1.0.3 y anteriores, [PKOBO-vote01] edición gratuita versiones 1.0.1 y anteriores, [Telop01] edición gratuita versión 1.0.0, [Gallery01] edición gratuita versiones 1.0.3 y anteriores, [CalendarForm01] edición gratuita versiones 1.0.3 y anteriores, y [Link01] edición gratuita versión 1.0.0, permite a atacantes remotos omitir la autenticación e iniciar sesión en el producto con privilegios administrativos por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:21:42.077",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:calendar01_project:calendar01:1.0.0:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "362A0450-C4C0-495A-96C9-5D16FD495C60"
            },
            {
              "criteria": "cpe:2.3:a:calendar02_project:calendar02:1.0.0:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8025765C-C495-4C77-93C4-628456D960F1"
            },
            {
              "criteria": "cpe:2.3:a:calendarform01_project:calendarform01:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31F5125D-A31B-4953-86EC-9F92866FA84E",
              "versionEndIncluding": "1.0.3"
            },
            {
              "criteria": "cpe:2.3:a:gallery01_project:gallery01:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FBE93BB-42C4-47EF-AA9C-22AB5A2326C8",
              "versionEndIncluding": "1.0.3"
            },
            {
              "criteria": "cpe:2.3:a:link01_project:link01:1.0.0:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01C4410F-5427-40B9-8FFA-1F01DF59D99F"
            },
            {
              "criteria": "cpe:2.3:a:pkobo-news01_project:pkobo-news01:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2552B4DC-7388-4CB0-9047-1F32BF12A71B",
              "versionEndIncluding": "1.0.3"
            },
            {
              "criteria": "cpe:2.3:a:pkobo-vote01_project:pkobo-vote01:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A4EDDC1-B85E-4D5C-8B83-8D066A143FC1",
              "versionEndIncluding": "1.0.1"
            },
            {
              "criteria": "cpe:2.3:a:telop01_project:telop01:1.0.0:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAD24BF8-A32E-44EF-A233-44ABB5283739"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}