Vulnerabilities
Vulnerable Software
Cybozu:  >> Garoon  >> 4.2.4  Security Vulnerabilities
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-08-29
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
CVSS Score
4.3
EPSS Score
0.013
Published
2017-08-29
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-07-07
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.
CVSS Score
4.8
EPSS Score
0.002
Published
2017-07-07


Contact Us

Shodan ® - All rights reserved