CVE-2020-5616
9.8
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.06% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-08-04 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| calendar01 project | calendar01 |
| calendar02 project | calendar02 |
| calendarform01 project | calendarform01 |
| gallery01 project | gallery01 |
| link01 project | link01 |
| pkobo-news01 project | pkobo-news01 |
| pkobo-vote01 project | pkobo-vote01 |
| telop01 project | telop01 |
References
- https://jvn.jp/en/jp/JVN73169744/index.html
- https://www.php-factory.net/calendar/01.php
- https://www.php-factory.net/calendar/02.php
- https://www.php-factory.net/calendar_form/01.php
- https://www.php-factory.net/gallery/01.php
- https://www.php-factory.net/link/01.php
- https://www.php-factory.net/news/pkobo-news01.php
- https://www.php-factory.net/telop/01.php
- https://www.php-factory.net/vote/01.php
- https://jvn.jp/en/jp/JVN73169744/index.html
- https://www.php-factory.net/calendar/01.php
- https://www.php-factory.net/calendar/02.php
- https://www.php-factory.net/calendar_form/01.php
- https://www.php-factory.net/gallery/01.php
- https://www.php-factory.net/link/01.php
- https://www.php-factory.net/news/pkobo-news01.php
- https://www.php-factory.net/telop/01.php
- https://www.php-factory.net/vote/01.php
→ the Explorer · watch your stack · NVD