Vulnerabilities > Cybozu > Office

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-39817 Unspecified vulnerability in Cybozu Office
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
network
low complexity
cybozu
6.5
2022-08-18 CVE-2022-25986 Unspecified vulnerability in Cybozu Office
Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.
network
low complexity
cybozu
4.3
2022-08-18 CVE-2022-28715 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
cybozu CWE-79
6.1
2022-08-18 CVE-2022-29487 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
cybozu CWE-79
6.1
2022-08-18 CVE-2022-29891 Unspecified vulnerability in Cybozu Office
Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vectors.
network
low complexity
cybozu
4.3
2022-08-18 CVE-2022-30604 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
network
low complexity
cybozu CWE-79
6.1
2022-08-18 CVE-2022-30693 Information Exposure vulnerability in Cybozu Office
Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to obtain the data of the product via unspecified vectors.
network
low complexity
cybozu CWE-200
5.3
2022-08-18 CVE-2022-32283 Unspecified vulnerability in Cybozu Office
Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Cabinet via unspecified vectors.
network
low complexity
cybozu
4.3
2022-08-18 CVE-2022-32453 Injection vulnerability in Cybozu Office
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.
network
low complexity
cybozu CWE-74
6.5
2022-08-18 CVE-2022-32544 Unspecified vulnerability in Cybozu Office
Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Project via unspecified vectors.
network
low complexity
cybozu
4.3