Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://support.cybozu.com/ja-jp/article/9812 | third party advisory |
http://jvn.jp/en/jp/JVN51737843/index.html | third party advisory |