VendorsCybozugaroon4.2.5
Vulnerabilities

Cybozu Garoon 4.2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-2257
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
Published 2017-08-28 · Modified
6.1EPSS 0.007
CVE-2017-2255
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
Published 2017-08-28 · Modified
5.4EPSS 0.005
CVE-2017-2256
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".
Published 2017-08-28 · Modified
5.4EPSS 0.005
CVE-2017-2254
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
Published 2017-08-28 · Modified
4.9EPSS 0.011
CVE-2017-2258
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
Published 2017-08-28 · Modified
4.3EPSS 0.013