CVE-2013-2305: CSRF
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2305?
CVE-2013-2305 has a medium severity rating due to its potential for CSRF attacks that can compromise user sessions.
How do I fix CVE-2013-2305?
To fix CVE-2013-2305, users should upgrade Cybozu Office to version 8.1.6 or later, Cybozu Dezie to version 8.0.7 or later, and Cybozu Mailwise to version 5.0.4 or later.
What software is affected by CVE-2013-2305?
CVE-2013-2305 affects Cybozu Office versions prior to 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4.
Can CVE-2013-2305 lead to unauthorized access?
Yes, CVE-2013-2305 can lead to unauthorized access as it allows attackers to hijack user authentication for password changes.
Is there a patch for CVE-2013-2305?
Yes, patches are available in the form of software updates for the affected versions of Cybozu products.