CVE-2016-4870
Cross-site scripting (XSS) vulnerability in “Schedule” function in Cybozu Office 9.0.0 through 10.4.0.
Read MoreCross-site scripting (XSS) vulnerability in “Schedule” function in Cybozu Office 9.0.0 through 10.4.0.
Read MoreThe “Project” function in Cybozu 9.0.0 through 10.4.0 allows remote authenticated users to read closed project information.
Read MoreCross-site scripting (XSS) vulnerability in the “Project” function in Cybozu Office 9.0.0 through 10.4.0.
Read MoreThe “breadcrumb trail” component in Cybozu Office 9.0.0 through 10.4.0 allows remote authenticated users to read the names of closed projects.
Read MoreThe “Project” function in Cybozu Office 9.0.0 through 10.4.0 does not properly check access permissions, which allows remote authenticated users to alter project information.
Read More