CVE-2019-5942

MEDIUM

Cybozu Garoon 4.0.0-4.10.1 - Authenticated Access Restriction Bypass via Multiple Files Download

Title source: llm
STIX 2.1

Description

Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN58849431/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/35485/

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
cybozu/garoon 4.0.0 - 4.10.1
Published May 17, 2019
Tracked Since Feb 18, 2026