CVE-2016-4868

MEDIUM

Cybozu Office - Improper Input Validation

Title source: rule

Description

Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

Scores

CVSS v3 4.3
EPSS 0.0067
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-20
Status published

Affected Products (17)

cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
... and 2 more

Timeline

Published Apr 17, 2017
Tracked Since Feb 18, 2026