CVE-2016-4868: Cybozu Office

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

Affected products

  • Cybozu Office: version 9.0 only; version 9.1.0 only; version 9.2.0 only; version 9.2.1 only; version 9.3.0 only; version 9.3.1 only; …

Published 2017-04-17. Last modified 2026-06-17.