CVE-2019-5977

CVSS v3 Score
4.3
Medium
CVSS v2 Score
4.0
Medium

Vulnerability Description

Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.

CVSS:4.3(Medium)

Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in doubl...

CWE-742017
CVSS:4.3(Medium)

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names c...

CWE-742018
CVSS:4.3(Medium)

cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

CWE-742018
CVSS:4.3(Medium)

A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. ...

CWE-742019
CVSS:4.3(Medium)

GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.

CWE-742020
CVSS:4.3(Medium)

Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized m...

CWE-742021