SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15502 SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-04T20:09:23.805Z

Reserved: 2019-01-10T00:00:00

Link: CVE-2019-5934

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-17T16:29:04.157

Modified: 2024-11-21T04:45:46.397

Link: CVE-2019-5934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.