CVE-2016-4868

MEDIUM

Cybozu Office 9.0.0-10.4.0 - Email Header Injection

Title source: llm
STIX 2.1

Description

Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
https://support.cybozu.com/ja-jp/article/9433
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97713
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN08736331/index.html
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000190.html

Scores

CVSS v3 4.3
EPSS 0.0067
EPSS Percentile 71.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-20
Status published
Products (16)
cybozu/office 9.0
cybozu/office 9.1.0
cybozu/office 9.2.0
cybozu/office 9.2.1
cybozu/office 9.3.0
cybozu/office 9.3.1
cybozu/office 9.3.2
cybozu/office 9.9.0
cybozu/office 10.0.0
cybozu/office 10.0.1
... and 6 more
Published Apr 17, 2017
Tracked Since Feb 18, 2026