PT-2019-17883 · Cybozu · Cybozu Garoon

Publicado

2019-05-17

·

Atualizado

2020-08-24

·

CVE-2019-5942

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Garoon versions 4.0.0 through 4.10.1
Description The issue allows remote authenticated attackers to bypass access restrictions and obtain files without proper access privileges. This is achieved through the Multiple Files Download function of the 'Cabinet' application.
Recommendations For versions 4.0.0 through 4.10.1, consider disabling the Multiple Files Download function of the 'Cabinet' application as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive files to prevent unauthorized access until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-5942

Produtos afetados

Cybozu Garoon