First published: Thu Apr 25 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Cybozu Office | <=8 | |
Cybozu Cybozu Office | =6 | |
Cybozu Cybozu Office | =7 | |
Cybozu Cybozu Office | =9 | |
Cybozu Cybozu Office | =9.2.1 | |
Cybozu Cybozu Dezie | <=8.0.6 | |
Cybozu Cybozu Dezie | =8.0.0 | |
Cybozu Cybozu Dezie | =8.0.1 | |
Cybozu Cybozu Dezie | =8.0.2 | |
Cybozu Cybozu Dezie | =8.0.3 | |
Cybozu Cybozu Dezie | =8.0.4 | |
Cybozu Cybozu Dezie | =8.0.5 | |
Cybozu Mailwise | <=5.0 | |
Cybozu Mailwise | =1.0 | |
Cybozu Mailwise | =2.0 | |
Cybozu Mailwise | =2.1 | |
Cybozu Mailwise | =3.0 | |
Cybozu Mailwise | =3.0\(0.2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2305 has a medium severity rating due to its potential for CSRF attacks that can compromise user sessions.
To fix CVE-2013-2305, users should upgrade Cybozu Office to version 8.1.6 or later, Cybozu Dezie to version 8.0.7 or later, and Cybozu Mailwise to version 5.0.4 or later.
CVE-2013-2305 affects Cybozu Office versions prior to 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4.
Yes, CVE-2013-2305 can lead to unauthorized access as it allows attackers to hijack user authentication for password changes.
Yes, patches are available in the form of software updates for the affected versions of Cybozu products.