The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39731.md | third party advisory |
https://liff.line.me/1657662489-pwEQNzJ4 | vendor advisory |