Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://jvn.jp/en/jp/JVN52694228/index.html | third party advisory |
https://kb.cybozu.support/article/37421 | vendor advisory |