CVE-2016-4868

EUVD-2016-5848
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
cybozuoffice
9.0
cybozuoffice
9.1.0
cybozuoffice
9.2.0
cybozuoffice
9.2.1
cybozuoffice
9.3.0
cybozuoffice
9.3.1
cybozuoffice
9.3.2
cybozuoffice
9.9.0
cybozuoffice
10.0.0
cybozuoffice
10.0.1
cybozuoffice
10.0.2
cybozuoffice
10.1.0
cybozuoffice
10.1.2
cybozuoffice
10.2.0
cybozuoffice
10.3.0
cybozuoffice
10.4.0
𝑥
= Vulnerable software versions