SQL Injection Vulnerability in Cybozu Garoon from Cybozu
CVE-2018-0607
8.8HIGH
What is CVE-2018-0607?
An SQL injection vulnerability exists in the Notifications application within Cybozu Garoon versions 3.5.0 through 4.6.2. This flaw permits remote authenticated users to manipulate the database by executing arbitrary SQL commands via certain vectors, which could potentially allow attackers to access sensitive data or disrupt the application's functionality.
Affected Version(s)
Cybozu Garoon 3.5.0 to 4.6.2