|
196631
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20765
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196632
|
5.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
|
CWE-20
Improper Input Validation
|
CVE-2021-20764
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196633
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.
|
NVD-CWE-Other
|
CVE-2021-20763
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196634
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.
|
CWE-20
Improper Input Validation
|
CVE-2021-20762
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196635
|
2.7 |
LOW
Network
|
cybozu
|
garoon
|
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privile…
|
CWE-20
Improper Input Validation
|
CVE-2021-20761
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196636
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.
|
CWE-20
Improper Input Validation
|
CVE-2021-20760
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196637
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
|
NVD-CWE-Other
|
CVE-2021-20759
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196638
|
8.0 |
HIGH
Network
|
cybozu
|
garoon
|
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitra…
|
CWE-352
Origin Validation Error
|
CVE-2021-20758
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196639
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
|
NVD-CWE-Other
|
CVE-2021-20757
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196640
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.
|
NVD-CWE-Other
|
CVE-2021-20756
|
2024-11-21 14:47 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|