CVE-2021-20807
https://notcve.org/view.php?id=CVE-2021-20807
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de administración de Cybozu Remote Service versiones 3.0.0 a 3.1.9, permite a un atacante remoto inyectar un script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37430 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-20806
https://notcve.org/view.php?id=CVE-2021-20806
Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Una vulnerabilidad de redireccionamiento abierto en Cybozu Remote Service versiones 3.0.0 a 3.1.9, permite a atacantes remotos redirigir a usuarios a sitios web arbitrarios y conducir ataques de phishing por medio de vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37419 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2021-20805
https://notcve.org/view.php?id=CVE-2021-20805
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo Cross-site scripting en la pantalla de administración de Cybozu Remote Service versiones 3.1.7 a 3.1.9, permite a un atacante remoto autenticado inyectar un script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37431 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-20804
https://notcve.org/view.php?id=CVE-2021-20804
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors. Cybozu Remote Service versiones 3.1.8 hasta 3.1.9 permite a un atacante remoto autenticado causar una condición de denegación de servicio (DoS) por medio de vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37426 •
CVE-2021-20803
https://notcve.org/view.php?id=CVE-2021-20803
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. Una omisión de la restricción de operaciones en la pantalla de administración de Cybozu Remote Service versiones 3.1.8 hasta 3.1.9, permite a un atacante remoto autenticado alterar los datos de la pantalla de administración • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37421 • CWE-863: Incorrect Authorization •