Lucene search

K
cve[email protected]CVE-2021-20876
HistoryDec 24, 2021 - 7:15 a.m.

CVE-2021-20876

2021-12-2407:15:06
CWE-22
web.nvd.nist.gov
27
cve
2021
20876
path traversal
vulnerability
groupsession
free edition
groupsession bycloud
groupsession zion
administrative privilege
sensitive information

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information stored in the hierarchy above the directory on the published site’s server via unspecified vectors.

Affected configurations

Vulners
NVD
Node
groupsessiongroupsession_bycloudMatch5.1.1
OR
groupsessiongroupsession_bycloudMatch5.1.1
OR
groupsessiongroupsession_bycloudMatch5.1.1
VendorProductVersionCPE
groupsessiongroupsession_bycloud5.1.1cpe:2.3:a:groupsession:groupsession_bycloud:5.1.1:*:*:*:*:*:*:*
groupsessiongroupsession_bycloud5.1.1cpe:2.3:a:groupsession:groupsession_bycloud:5.1.1:*:*:*:*:*:*:*
groupsessiongroupsession_bycloud5.1.1cpe:2.3:a:groupsession:groupsession_bycloud:5.1.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "GroupSession Free edition, GroupSession byCloud, GroupSession ZION",
    "vendor": "Japan Total System Co.,Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

6.5 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Related for CVE-2021-20876