CVE-2016-4868
MEDIUMCybozu Office - Improper Input Validation
Title source: ruleDescription
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
References (4)
Scores
CVSS v3
4.3
EPSS
0.0067
EPSS Percentile
71.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-20
Status
published
Affected Products (17)
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
... and 2 more
Timeline
Published
Apr 17, 2017
Tracked Since
Feb 18, 2026