PT-2022-21386 · Cybozu · Cybozu Office

Yuji Tounai

·

Published

2022-08-18

·

Updated

2023-08-08

·

CVE-2022-32583

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Office versions 10.0.0 through 10.8.5
Description The issue allows a remote authenticated attacker to bypass operation restrictions in the Scheduler component of Cybozu Office, enabling them to alter Scheduler data via unspecified vectors.
Recommendations For Cybozu Office versions 10.0.0 through 10.8.5, update to a version that contains a fix for this issue to prevent unauthorized data alterations in the Scheduler component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-32583

Affected Products

Cybozu Office