CVE-2016-1218: SQL Injection
Published Apr 20, 2017
·Updated
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
Affected Software
1 affected component
Cybozu Garoon<=4.2.1
Event History
Apr 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1218?
CVE-2016-1218 has a medium severity rating due to its potential for SQL injection exploitation.
2
How do I fix CVE-2016-1218?
To fix CVE-2016-1218, upgrade Cybozu Garoon to version 4.2.2 or later.
3
What is the impact of exploiting CVE-2016-1218?
Exploiting CVE-2016-1218 can allow an attacker to execute arbitrary SQL commands on the database.
4
Who is affected by CVE-2016-1218?
CVE-2016-1218 affects users of Cybozu Garoon versions up to and including 4.2.1.
5
Is there a workaround for CVE-2016-1218 if I cannot upgrade?
There is no specific workaround for CVE-2016-1218; upgrading is the recommended action.