CVE-2015-5647

Cybozu Garoon <4.0.3 - Authenticated RCE

Title source: llm
STIX 2.1

Description

The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVDB-866.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000151
Vendor Advisory x_refsource_confirm
https://support.cybozu.com/ja-jp/article/8810
Vendor Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN21025396/index.html
Vendor Advisory x_refsource_confirm
http://jvn.jp/en/jp/JVN21025396/374951/index.html

Scores

EPSS 0.0066
EPSS Percentile 71.4%

Details

CWE
CWE-94
Status published
Products (24)
cybozu/garoon 3.0.0
cybozu/garoon 3.0.1
cybozu/garoon 3.0.2
cybozu/garoon 3.0.3
cybozu/garoon 3.1.0
cybozu/garoon 3.1.1
cybozu/garoon 3.1.2
cybozu/garoon 3.1.3
cybozu/garoon 3.5.0
cybozu/garoon 3.5.1
... and 14 more
Published Oct 12, 2015
Tracked Since Feb 18, 2026