Improper Access Control in Bulletin Board of Cybozu Office by Cybozu
CVE-2021-20625

4.3MEDIUM

Key Information:

Vendor

Cybozu

Vendor
CVE Published:
18 March 2021

What is CVE-2021-20625?

This vulnerability in the Bulletin Board feature of Cybozu Office versions 10.0.0 to 10.8.4 allows an authenticated attacker to circumvent access restrictions. As a result, the attacker can manipulate Bulletin Board data through various unspecified methods, posing significant risks to data integrity and security for users.

Affected Version(s)

Cybozu Office 10.0.0 to 10.8.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.