PT-2024-28682 · Cybozu · Cybozu Office
Published
2024-08-06
·
Updated
2024-09-11
·
CVE-2024-39817
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cybozu Office versions 10.0.0 through 10.8.6
Description
The issue allows a user who can login to the product to view data that the user does not have access to by conducting 'search' under certain conditions in Custom App. This is due to the insertion of sensitive information into sent data.
Recommendations
For Cybozu Office versions 10.0.0 through 10.8.6, consider restricting access to the Custom App search function until a patch is available. As a temporary workaround, limit user privileges to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cybozu Office