Vulnerabilities > Cybozu > Garoon > Low

DATE CVE VULNERABILITY TITLE RISK
2022-07-04 CVE-2022-29513 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary script.
network
cybozu CWE-79
3.5
2021-08-18 CVE-2021-20774 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2021-08-18 CVE-2021-20770 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2021-08-18 CVE-2021-20769 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2021-08-18 CVE-2021-20767 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2021-08-18 CVE-2021-20761 Improper Input Validation vulnerability in Cybozu Garoon
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.
network
cybozu CWE-20
3.5
2021-08-18 CVE-2021-20753 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2020-06-30 CVE-2020-5585 Cross-site Scripting vulnerability in Cybozu Garoon 5.0.0/5.0.1
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2020-06-30 CVE-2020-5586 Cross-site Scripting vulnerability in Cybozu Garoon 4.10.3/5.0.0/5.0.1
Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.
network
cybozu CWE-79
3.5
2019-09-12 CVE-2019-5975 Cross-site Scripting vulnerability in Cybozu Garoon
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
cybozu CWE-79
3.5