CVE-2021-20802
https://notcve.org/view.php?id=CVE-2021-20802
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. Una vulnerabilidad de inyección del encabezado HTTP en Cybozu Remote Service versiones 3.1.8 hasta 3.1.9 permite a un atacante remoto alterar la información almacenada en el producto • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37428 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2021-20801
https://notcve.org/view.php?id=CVE-2021-20801
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox. Cybozu Remote Service versiones 3.1.8 hasta 3.1.9 permite a un atacante remoto autenticado conducir ataques de tipo XML External Entity (XXE) y obtener la información almacenada en el producto por medio de vectores no especificados. Este problema sólo se produce cuando es usado Mozilla Firefox • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37423 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2021-20799
https://notcve.org/view.php?id=CVE-2021-20799
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de administración de Cybozu Remote Service versiones 3.1.8 hasta 3.1.9, permite a un atacante remoto autenticado inyectar un script arbitrario por vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37425 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-20798
https://notcve.org/view.php?id=CVE-2021-20798
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. Una vulnerabilidad de tipo cross-site scripting en la pantalla de administración de Cybozu Remote Service versiones 3.1.8 hasta 3.1.9, permite a un atacante remoto autenticado inyectar un script arbitrario por vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37424 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-20795
https://notcve.org/view.php?id=CVE-2021-20795
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en la pantalla de administración de Cybozu Remote Service versiones 3.1.8 hasta 3.1.9, permite a un atacante remoto secuestrar la autenticación de los administradores y pueden llevarse a cabo operaciones no deseadas por medio de vectores no especificados • https://jvn.jp/en/jp/JVN52694228/index.html https://kb.cybozu.support/article/37422 • CWE-352: Cross-Site Request Forgery (CSRF) •