Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN29845579/ | Third Party Advisory |
https://kb.cybozu.support/?product=office&v=&fv=10.8.7&t=%E8%84%86%E5%BC%B1%E6%80%A7&s= | Vendor Advisory |
Configurations
History
18 Mar 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-200 |
Information
Published : 2024-08-06 05:15
Updated : 2025-03-18 21:15
NVD link : CVE-2024-39817
Mitre link : CVE-2024-39817
CVE.ORG link : CVE-2024-39817
JSON object : View
Products Affected
cybozu
- office
CWE