CVE-2019-5930
https://notcve.org/view.php?id=CVE-2019-5930
Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'. Cybozu Garoon 4.0.0 a 4.6.3 permite a los atacantes remotos eludir el Access Restriction para navegar por páginas no autorizadas a través de la aplicación 'Management of Basic System'. • http://jvn.jp/en/jp/JVN58849431/index.html https://kb.cybozu.support/article/34227 •
CVE-2019-5931
https://notcve.org/view.php?id=CVE-2019-5931
Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors. Cybozu Garoon 4.0.0 a 4.6.3 permite a los atacantes autenticados alterar la información con privilegios invocando el Installer por medio de vectores no especificados. • http://jvn.jp/en/jp/JVN58849431/index.html https://kb.cybozu.support/article/34283 • CWE-20: Improper Input Validation •
CVE-2019-5929
https://notcve.org/view.php?id=CVE-2019-5929
Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via the application 'Memo'. La vulnerabilidad del tipo Cross-Site Scripting en Cybozu Garoon 4.0.0 a 4.6.3 permite a los atacantes remotos inyectar scripts web o HTML a través de la aplicación 'Memo'. • http://jvn.jp/en/jp/JVN58849431/index.html https://kb.cybozu.support/article/34277 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-5928
https://notcve.org/view.php?id=CVE-2019-5928
Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via Customize Item function. La vulnerabilidad del tipo Cross-Site Scripting en Cybozu Garoon 4.0.0 a 4.6.3 permite a los atacantes remotos inyectar secuencias de comandos web o HTML a través de la función Customize Item. • http://jvn.jp/en/jp/JVN58849431/index.html https://jvn.jp/en/jp/JVN58849431 https://kb.cybozu.support/article/34279 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-16178
https://notcve.org/view.php?id=CVE-2018-16178
Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function. Cybozu Garoon, desde la versión 3.0.0 hasta la 4.10.0, permite que atacantes remotos omitan las restricciones de acceso para ver información disponible solo para un usuario "sign-on" mediante la función Single sign-on. • https://jvn.jp/en/jp/JVN25385698/index.html https://kb.cybozu.support/article/35265 •