CVE-2020-5643
https://notcve.org/view.php?id=CVE-2020-5643
Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector. La vulnerabilidad de validación de entrada inapropiada en Cybozu Garoon versión 5.0.0 hasta 5.0.2, permite a un atacante autenticado remoto eliminar algunos datos del tablero de anuncios por medio de un vector no especificado • https://jvn.jp/en/jp/JVN57942454/index.html https://kb.cybozu.support/article/36725 • CWE-20: Improper Input Validation •
CVE-2020-5587
https://notcve.org/view.php?id=CVE-2020-5587
Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors. Cybozu Garoon versiones 4.0.0 hasta 5.0.1, permite a atacantes autenticados remotos obtener información no deseada por medio de vectores no especificados • https://jvn.jp/en/jp/JVN55497111/index.html https://kb.cybozu.support/article/36409 •
CVE-2020-5588
https://notcve.org/view.php?id=CVE-2020-5588
Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors. Una vulnerabilidad de salto de ruta en Cybozu Garoon versiones 5.0.0 hasta 5.0.1, permite a un atacante con derechos de administrador obtener información no deseada por medio de vectores no especificados • https://jvn.jp/en/jp/JVN55497111/index.html https://kb.cybozu.support/article/36410 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-5585
https://notcve.org/view.php?id=CVE-2020-5585
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en Cybozu Garoon versiones 5.0.0 hasta 5.0.1, permite a un atacante con derechos de administrador inyectar un script arbitrario por medio de vectores no especificados • https://jvn.jp/en/jp/JVN55497111/index.html https://kb.cybozu.support/article/36432 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-5586
https://notcve.org/view.php?id=CVE-2020-5586
Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en Cybozu Garoon versiones 4.10.3 hasta 5.0.1, permite a un atacante con derechos de administrador inyectar script arbitrarios por medio de vectores no especificados • https://jvn.jp/en/jp/JVN55497111/index.html https://kb.cybozu.support/article/36453 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •