Skip to main content

Vendor archive

cybozu CVEs

Beta · best-effort

330 CVEs tagged to vendor cybozu8 Critical, 37 High, 269 Medium, 16 Low, 0 Unrated.

CVE-2021-20764

Published Aug 18, 2021

Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20763

Published Aug 18, 2021

Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20762

Published Aug 18, 2021

Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20761

Published Aug 18, 2021

Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-20760

Published Aug 18, 2021

Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the approp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20759

Published Aug 18, 2021

Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20758

Published Aug 18, 2021

Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators an…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20757

Published Aug 18, 2021

Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20756

Published Aug 18, 2021

Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20755

Published Aug 18, 2021

Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privile…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20754

Published Aug 18, 2021

Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20753

Published Aug 18, 2021

Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20634

Published Mar 18, 2021

Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20633

Published Mar 18, 2021

Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20632

Published Mar 18, 2021

Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bullet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20631

Published Mar 18, 2021

Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20630

Published Mar 18, 2021

Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20629

Published Mar 18, 2021

Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20628

Published Mar 18, 2021

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20627

Published Mar 18, 2021

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20626

Published Mar 18, 2021

Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20625

Published Mar 18, 2021

Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulle…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20624

Published Mar 18, 2021

Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Scheduler…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5643

Published Nov 6, 2020

Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5588

Published Jun 30, 2020

Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 330 CVEsPage 4 of 14