|
195831
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.
|
NVD-CWE-noinfo
|
CVE-2021-20773
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195832
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.
|
NVD-CWE-Other
|
CVE-2021-20772
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195833
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20771
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195834
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20770
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195835
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20769
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195836
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport witho…
|
NVD-CWE-Other
|
CVE-2021-20768
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195837
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20767
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195838
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20766
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195839
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20765
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195840
|
5.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
|
CWE-20
Improper Input Validation
|
CVE-2021-20764
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|