CVE-2019-5934

HIGH

Cybozu Garoon 4.0.0-4.10.0 - Authenticated SQL Injection via Log Search Function

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35306/

Scores

CVSS v3 7.2
EPSS 0.0032
EPSS Percentile 55.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
cybozu/garoon 4.0.0 - 4.10.0
Published May 17, 2019
Tracked Since Feb 18, 2026