
CVE-2017-2091
https://notcve.org/view.php?id=CVE-2017-2091
28 Apr 2017 — Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors. Cybozu Garoon 3.0.0 hasta 4.2.3 permiten a un atacante remoto autenticado sortear la restricción de acceso en la función Phone Messages para alterar el estado de los mensajes del teléfono a través de vectores no especificados. • http://jvn.jp/en/jp/JVN73182875/index.html •

CVE-2017-2092
https://notcve.org/view.php?id=CVE-2017-2092
28 Apr 2017 — Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de cross-site scripting en Cybozu Garoon 3.0.0 hasta 4.2.3 permite a un atacante remoto autenticado inyectar script web o HTML a través de vectores no especificados. • http://jvn.jp/en/jp/JVN73182875/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-2093
https://notcve.org/view.php?id=CVE-2017-2093
28 Apr 2017 — Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors. Cybozu Garoon 3.0.0 hasta 4.2.3 permite a un atacante remoto obtener tokens utilizados por la protección CSRF a través de vectores no especificados. • http://jvn.jp/en/jp/JVN73182875/index.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-2094
https://notcve.org/view.php?id=CVE-2017-2094
28 Apr 2017 — Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors. Cybozu Garoon 3.0.0 hasta 4.2.3 permite a un atacante remoto autenticado sortear la restricción de acceso en Workflow y la función "MultiRepor" para alterar o borrar información a través de vectores no especificados. • http://jvn.jp/en/jp/JVN73182875/index.html • CWE-269: Improper Privilege Management •

CVE-2017-2095
https://notcve.org/view.php?id=CVE-2017-2095
28 Apr 2017 — Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors. Cybozu Garoon 3.0.0 hasta 4.2.3 permiten a un atacante remoto autenticado sortear la restricción de acceso en la función mail, consiguiendo una alteración del orden de las carpetas de correo a través de vectores no especificados. • http://jvn.jp/en/jp/JVN73182875/index.html •

CVE-2016-1213
https://notcve.org/view.php?id=CVE-2016-1213
20 Apr 2017 — The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. La función "Scheduler" en Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos redirigir a los usuarios a sitios web arbitrarios. • http://jvn.jp/en/jp/JVN67266823/index.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2016-1214
https://notcve.org/view.php?id=CVE-2016-1214
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Response request" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1215
https://notcve.org/view.php?id=CVE-2016-1215
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "User details" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1216
https://notcve.org/view.php?id=CVE-2016-1216
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "New appointment" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1217
https://notcve.org/view.php?id=CVE-2016-1217
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Check available times" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •