CVE-2020-5582

MEDIUM

Cybozu Garoon 4.0.0-5.0.1 - Authenticated Access Restriction Bypass in Report File Attachment

Title source: llm
STIX 2.1

Description

Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://jvn.jp/en/jp/JVN55497111/index.html
Vendor Advisory x_refsource_misc
https://kb.cybozu.support/article/36455/

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (1)
cybozu/garoon 4.0.0 - 5.0.1
Published Jun 30, 2020
Tracked Since Feb 18, 2026