CVE-2013-3269: Cybozu Office

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mobile passwords, a different vulnerability than CVE-2013-2305.

Affected products

  • Cybozu Cybozu Office: up to and including 8; version 6 only; version 7 only; version 9 only; version 9.2.1 only

Published 2013-04-25. Last modified 2026-06-16.