CVE-2016-1151: CSRF
Published Feb 17, 2016
·Updated
Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.
Affected Software
8 affected components
Cybozu Office=9.9.0
Cybozu Office=10.0.0
Cybozu Office=10.0.1
Cybozu Office=10.0.2
Cybozu Office=10.1.0
Cybozu Office=10.1.2
Cybozu Office=10.2.0
Cybozu Office=10.3.0
Event History
Feb 17, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1151?
CVE-2016-1151 is classified as a high severity vulnerability due to its potential for remote attacks and user authentication hijacking.
2
How do I fix CVE-2016-1151?
To fix CVE-2016-1151, users should upgrade Cybozu Office to the latest version that is not affected by this vulnerability.
3
Which versions of Cybozu Office are affected by CVE-2016-1151?
CVE-2016-1151 affects Cybozu Office versions 9.9.0 to 10.3.0.
4
What type of attacks are possible with CVE-2016-1151?
CVE-2016-1151 allows attackers to perform cross-site request forgery (CSRF) attacks, potentially hijacking user sessions.
5
Who can be impacted by CVE-2016-1151?
Any user of Cybozu Office versions 9.9.0 through 10.3.0 could be impacted by CVE-2016-1151 if they are targeted by CSRF attacks.