Vulnerabilities
Vulnerable Software
Cybozu:  >> Cybozu Office  >> 7  Security Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.
CVSS Score
6.8
EPSS Score
0.001
Published
2013-04-25
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mobile passwords, a different vulnerability than CVE-2013-2305.
CVSS Score
6.8
EPSS Score
0.002
Published
2013-04-25
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
CVSS Score
5.8
EPSS Score
0.004
Published
2010-05-24


Contact Us

Shodan ® - All rights reserved