Cross-Site Request Forgery Vulnerability in Cybozu Remote Service
CVE-2021-20795
8.8HIGH
What is CVE-2021-20795?
A cross-site request forgery vulnerability in the management screen of Cybozu Remote Service versions 3.1.8 and 3.1.9 allows remote attackers to exploit session hijacking. By tricking administrators into interacting with malicious contents, attackers can perform unintended operations, compromising the integrity of the management process. This vulnerability highlights the critical importance of implementing secure request verification and robust authentication mechanisms to safeguard against unauthorized actions.
Affected Version(s)
Cybozu Remote Service 3.1.8 to 3.1.9