Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://jvn.jp/en/jp/JVN14631222/index.html | vdb entry third party advisory |
http://www.securityfocus.com/bid/97912 | vdb entry third party advisory |
http://www.securityfocus.com/bid/94966 | vdb entry third party advisory |
https://support.cybozu.com/ja-jp/article/9399 | vendor advisory |