Vulnerabilities > Cybozu > Garoon > 5.5.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-07-04 | CVE-2022-29471 | Unspecified vulnerability in Cybozu Garoon Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin. | 4.3 |
2022-07-04 | CVE-2022-29484 | Unspecified vulnerability in Cybozu Garoon Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space. | 8.1 |
2022-07-04 | CVE-2022-29513 | Cross-site Scripting vulnerability in Cybozu Garoon Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary script. | 4.8 |
2022-07-04 | CVE-2022-29892 | Improper Input Validation vulnerability in Cybozu Garoon Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS). | 6.5 |
2021-08-18 | CVE-2021-20771 | Cross-site Scripting vulnerability in Cybozu Garoon Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. | 6.1 |
2021-08-18 | CVE-2021-20772 | Unspecified vulnerability in Cybozu Garoon Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege. | 4.3 |
2021-08-18 | CVE-2021-20773 | Unspecified vulnerability in Cybozu Garoon There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege. | 4.3 |
2021-08-18 | CVE-2021-20774 | Cross-site Scripting vulnerability in Cybozu Garoon Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | 5.4 |
2021-08-18 | CVE-2021-20775 | Improper Input Validation vulnerability in Cybozu Garoon Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege. | 4.3 |