CVE-2016-4869

Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to obtain session information from users.

CVE-2016-4870

Cross-site scripting (XSS) vulnerability in “Schedule” function in Cybozu Office 9.0.0 through 10.4.0.

CVE-2016-4867

The “Project” function in Cybozu 9.0.0 through 10.4.0 allows remote authenticated users to read closed project information.

CVE-2016-4866

Cross-site scripting (XSS) vulnerability in the “Project” function in Cybozu Office 9.0.0 through 10.4.0.

CVE-2016-4872

The “breadcrumb trail” component in Cybozu Office 9.0.0 through 10.4.0 allows remote authenticated users to read the names of closed projects.

CVE-2016-4873

The “Project” function in Cybozu Office 9.0.0 through 10.4.0 does not properly check access permissions, which allows remote authenticated users to alter project information.