Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://cs.cybozu.co.jp/2024/007901.html | vendor advisory |
https://jvn.jp/en/jp/JVN28869536/ | third party advisory |