Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN73182875/index.html | vdb entry third party advisory |
https://support.cybozu.com/ja-jp/article/9647 | vendor advisory |
http://www.securityfocus.com/bid/96429 | vdb entry third party advisory |