Vulnerability Details CVE-2016-4908
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.7%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2016-4908
-
cpe:2.3:a:cybozu:garoon:3.0.0
-
cpe:2.3:a:cybozu:garoon:3.0.1
-
cpe:2.3:a:cybozu:garoon:3.0.2
-
cpe:2.3:a:cybozu:garoon:3.0.3
-
cpe:2.3:a:cybozu:garoon:3.1.0
-
cpe:2.3:a:cybozu:garoon:3.1.1
-
cpe:2.3:a:cybozu:garoon:3.1.2
-
cpe:2.3:a:cybozu:garoon:3.1.3
-
cpe:2.3:a:cybozu:garoon:3.5.0
-
cpe:2.3:a:cybozu:garoon:3.5.1
-
cpe:2.3:a:cybozu:garoon:3.5.2
-
cpe:2.3:a:cybozu:garoon:3.5.3
-
cpe:2.3:a:cybozu:garoon:3.5.4
-
cpe:2.3:a:cybozu:garoon:3.5.5
-
cpe:2.3:a:cybozu:garoon:3.7.0
-
cpe:2.3:a:cybozu:garoon:3.7.1
-
cpe:2.3:a:cybozu:garoon:3.7.2
-
cpe:2.3:a:cybozu:garoon:3.7.3
-
cpe:2.3:a:cybozu:garoon:3.7.4
-
cpe:2.3:a:cybozu:garoon:3.7.5
-
cpe:2.3:a:cybozu:garoon:4.0.0
-
cpe:2.3:a:cybozu:garoon:4.0.1
-
cpe:2.3:a:cybozu:garoon:4.0.2
-
cpe:2.3:a:cybozu:garoon:4.0.3
-
cpe:2.3:a:cybozu:garoon:4.2.0
-
cpe:2.3:a:cybozu:garoon:4.2.1
-
cpe:2.3:a:cybozu:garoon:4.2.2