Vulnerabilities > Cybozu > Garoon > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-18 | CVE-2021-20771 | Cross-site Scripting vulnerability in Cybozu Garoon Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. | 6.1 |
2021-08-18 | CVE-2021-20772 | Unspecified vulnerability in Cybozu Garoon Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege. | 4.3 |
2021-08-18 | CVE-2021-20773 | Unspecified vulnerability in Cybozu Garoon There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege. | 4.3 |
2021-08-18 | CVE-2021-20774 | Cross-site Scripting vulnerability in Cybozu Garoon Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | 5.4 |
2021-08-18 | CVE-2021-20775 | Improper Input Validation vulnerability in Cybozu Garoon Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege. | 4.3 |
2020-11-06 | CVE-2020-5643 | Improper Input Validation vulnerability in Cybozu Garoon 5.0.0/5.0.1/5.0.2 Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector. | 6.5 |
2020-06-30 | CVE-2020-5588 | Path Traversal vulnerability in Cybozu Garoon 5.0.0/5.0.1 Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors. | 4.9 |
2020-06-30 | CVE-2020-5587 | Unspecified vulnerability in Cybozu Garoon Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors. | 6.5 |
2020-06-30 | CVE-2020-5586 | Cross-site Scripting vulnerability in Cybozu Garoon 4.10.3/5.0.0/5.0.1 Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors. | 4.8 |
2020-06-30 | CVE-2020-5585 | Cross-site Scripting vulnerability in Cybozu Garoon 5.0.0/5.0.1 Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors. | 4.8 |