CVE-2018-0607: SQL Injection
Published Jul 26, 2018
·Updated
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
1 affected component
Cybozu Garoon>=3.5.0<=4.6.2
Event History
Jul 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0607?
CVE-2018-0607 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2018-0607?
To fix CVE-2018-0607, update Cybozu Garoon to a version later than 4.6.2.
3
What versions of Cybozu Garoon are affected by CVE-2018-0607?
CVE-2018-0607 affects Cybozu Garoon versions from 3.5.0 to 4.6.2.
4
Can CVE-2018-0607 be exploited remotely?
Yes, CVE-2018-0607 can be exploited remotely by authenticated attackers.
5
What type of vulnerability is CVE-2018-0607?
CVE-2018-0607 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.