Cross-Site Request Forgery in Cybozu Garoon Product
CVE-2016-4907

8.8HIGH

Key Information:

Vendor

Cybozu

Vendor
CVE Published:
9 June 2017

What is CVE-2016-4907?

A security flaw in Cybozu Garoon versions 3.0.0 to 4.2.2 allows remote attackers to exploit Cross-Site Request Forgery (CSRF). This vulnerability grants unauthorized access to CSRF tokens through unspecified vectors, potentially exposing sensitive information. It is critical for users of these versions to implement preventive measures and updates to safeguard against unauthorized access.

Affected Version(s)

Cybozu Garoon 3.0.0 to 4.2.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.