CVE-2016-4868

Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
cybozuoffice
9.0
cybozuoffice
9.1.0
cybozuoffice
9.2.0
cybozuoffice
9.2.1
cybozuoffice
9.3.0
cybozuoffice
9.3.1
cybozuoffice
9.3.2
cybozuoffice
9.9.0
cybozuoffice
10.0.0
cybozuoffice
10.0.1
cybozuoffice
10.0.2
cybozuoffice
10.1.0
cybozuoffice
10.1.2
cybozuoffice
10.2.0
cybozuoffice
10.3.0
cybozuoffice
10.4.0
𝑥
= Vulnerable software versions