CVE-2019-5935: Cybozu Garoon
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.
Affected products
- Cybozu Garoon: from 4.0.0, up to and including 4.10.1
Published 2019-05-17. Last modified 2026-06-17.