Page 2 of 43 results (0.011 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "User details" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000144.html http://www.securityfocus.com/bid/92601 https://support.cybozu.com/ja-jp/article/9223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cybozu Garoon before 4.2.2 does not properly restrict access. Cybozu Garoon en versiones anteriores a 4.2.2 no restringe correctamente el acceso. • http://jvn.jp/en/jp/JVN93411577/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000149.html http://www.securityfocus.com/bid/92599 https://support.cybozu.com/ja-jp/article/9407 • CWE-284: Improper Access Control •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000148.html http://www.securityfocus.com/bid/92598 https://support.cybozu.com/ja-jp/article/9408 • CWE-287: Improper Authentication •

CVSS: 3.5EPSS: 0%CPEs: 27EXPL: 0

Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en el portlet Notices en Cybozu Garoon 2.x y 3.x anterior a 3.7 SP4 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://cs.cybozu.co.jp/information/gr20140714up04.php http://jvn.jp/en/jp/JVN80583739/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000076 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 3.5EPSS: 0%CPEs: 27EXPL: 0

Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la funcionalidad Map Search en Cybozu Garoon 2.x y 3.x anterior a 3.7 SP4 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://cs.cybozu.co.jp/information/gr20140714up02.php http://jvn.jp/en/jp/JVN97558950/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000075 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •