Описание
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
Ссылки
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.0.0 (включая) до 10.8.7 (исключая)
cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00543
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-200
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
EPSS
Процентиль: 67%
0.00543
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-200