CVE Published: 24/12/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: Japan Total System Co.,Ltd. |
Product: GroupSession Free edition, GroupSession byCloud, GroupSession ZION Status : PUBLISHED
CVE-2021-20874 Description
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access arbitrary files on the server and obtain sensitive information via unspecified vectors.