CVE-2018-0607

HIGH

Cybozu Garoon 3.5.0-4.6.2 - Authenticated SQL Injection in Notifications Application

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN13415512/index.html
Vendor Advisory x_refsource_confirm
https://kb.cybozu.support/article/33120/

Scores

CVSS v3 8.8
EPSS 0.0064
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
cybozu/garoon 3.5.0 - 4.6.2
Published Jul 26, 2018
Tracked Since Feb 18, 2026