The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN67266823/index.html | vdb entry third party advisory |
http://www.securityfocus.com/bid/92596 | vdb entry third party advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000142 | vdb entry third party advisory |
https://support.cybozu.com/ja-jp/article/9221 | vendor advisory |