CVE-2020-5565
- EPSS 0.24%
- Veröffentlicht 28.04.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:16
Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.
CVE-2020-5566
- EPSS 0.26%
- Veröffentlicht 28.04.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:17
Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'.
CVE-2020-5567
- EPSS 0.81%
- Veröffentlicht 28.04.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:17
Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Application Menu.
CVE-2020-5568
- EPSS 0.4%
- Veröffentlicht 28.04.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:17
Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 5.0.0 allows remote attackers to inject arbitrary web script or HTML via the applications 'Messages' and 'Bulletin Board'.
CVE-2019-5991
- EPSS 0.44%
- Veröffentlicht 12.09.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:45:52
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2019-5975
- EPSS 0.2%
- Veröffentlicht 12.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:45:50
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2019-5976
- EPSS 0.3%
- Veröffentlicht 12.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:45:50
Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.
CVE-2019-5977
- EPSS 0.2%
- Veröffentlicht 12.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:45:50
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
CVE-2019-5978
- EPSS 0.27%
- Veröffentlicht 12.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:45:50
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
CVE-2019-5944
- EPSS 0.18%
- Veröffentlicht 17.05.2019 16:29:05
- Zuletzt bearbeitet 21.11.2024 04:45:47
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.