CVE-2016-1191

MEDIUM

Cybozu Garoon <4.2.1 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000078
Vendor Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN14749391/index.html
Patch, Vendor Advisory x_refsource_confirm
https://garoon.cybozu.co.jp/support/update/package/421sp1.html#03

Scores

CVSS v3 5.3
EPSS 0.0060
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-22
Status published
Products (25)
cybozu/garoon 3.0.0
cybozu/garoon 3.0.1
cybozu/garoon 3.0.2
cybozu/garoon 3.0.3
cybozu/garoon 3.1.0
cybozu/garoon 3.1.1
cybozu/garoon 3.1.2
cybozu/garoon 3.1.3
cybozu/garoon 3.5.0
cybozu/garoon 3.5.1
... and 15 more
Published Jun 19, 2016
Tracked Since Feb 18, 2026