Vulnerabilities
Vulnerable Software
Cybozu:  Security Vulnerabilities
Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-02-02
Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
CVSS Score
6.8
EPSS Score
0.002
Published
2026-02-02
Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.
CVSS Score
6.9
EPSS Score
0.004
Published
2026-02-02
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
CVSS Score
6.5
EPSS Score
0.004
Published
2024-08-06
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.
CVSS Score
5.4
EPSS Score
0.002
Published
2024-07-19
Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.
CVSS Score
4.9
EPSS Score
0.005
Published
2024-06-11
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
CVSS Score
4.3
EPSS Score
0.003
Published
2024-06-11
Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.
CVSS Score
6.5
EPSS Score
0.004
Published
2024-06-11
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
CVSS Score
4.3
EPSS Score
0.003
Published
2024-06-11
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
CVSS Score
6.5
EPSS Score
0.003
Published
2024-06-11


Contact Us

Shodan ® - All rights reserved