CVE-2024-39817: Infoleak
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39817?
CVE-2024-39817 has been rated as a medium severity vulnerability due to its potential to expose sensitive information to unauthorized users.
How do I fix CVE-2024-39817?
To fix CVE-2024-39817, update Cybozu Office to version 10.8.7 or later, which addresses this issue.
Who is affected by CVE-2024-39817?
CVE-2024-39817 affects users of Cybozu Office versions 10.0.0 to 10.8.6.
What is the impact of CVE-2024-39817?
The impact of CVE-2024-39817 is that a logged-in user may gain access to data they should not have permission to view under specific conditions.
When was CVE-2024-39817 reported?
CVE-2024-39817 was reported in 2024 and is applicable to a range of versions of Cybozu Office.