Show filters
197 Total Results
Displaying 71-80 of 197
Sort by:
Attacker Value
Unknown

CVE-2020-5565

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.
Attacker Value
Unknown

CVE-2019-5975

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2019-5976

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.
Attacker Value
Unknown

CVE-2019-5977

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
Attacker Value
Unknown

CVE-2019-5991

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Attacker Value
Unknown

CVE-2019-5978

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
Attacker Value
Unknown

CVE-2019-5931

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.
0
Attacker Value
Unknown

CVE-2019-5942

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.
0
Attacker Value
Unknown

CVE-2019-5932

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Portal'.
0
Attacker Value
Unknown

CVE-2019-5933

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.
0