Vulnerabilities > Cybozu > Garoon > 4.2.5

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-2255 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
network
low complexity
cybozu CWE-79
5.4
2017-08-29 CVE-2017-2254 Improper Input Validation vulnerability in Cybozu Garoon
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
network
low complexity
cybozu CWE-20
4.9