Privilege Escalation in Cybozu Garoon 3.0.0 to 4.2.2: Unauthorized Modification of User's Private RSS Settings

Privilege Escalation in Cybozu Garoon 3.0.0 to 4.2.2: Unauthorized Modification of User's Private RSS Settings

CVE-2016-4908 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.

Learn more about our User Device Pen Test.