First published: Wed Jan 29 2014(Updated: )
SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | =3.7.0 | |
Cybozu Garoon | =3.7.1 | |
Cybozu Garoon | =3.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6931 is classified as a medium severity vulnerability due to its potential for executing arbitrary SQL commands.
To fix CVE-2013-6931, upgrade Cybozu Garoon to version 3.7.3 or later.
CVE-2013-6931 affects remote authenticated users of Cybozu Garoon versions 3.7.0, 3.7.1, and 3.7.2.
CVE-2013-6931 is an SQL injection vulnerability that allows unauthorized access to the database.
While no specific exploits are publicly documented, the nature of SQL injection suggests potential risks if the vulnerability is exploited.