PT-2017-15301 · Cybozu · Cybozu Garoon

Published

2017-08-28

·

Updated

2017-08-30

·

CVE-2017-2255

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Garoon versions 3.7.0 through 4.2.5
Description A cross-site scripting issue exists, allowing an attacker to inject arbitrary web script or HTML via the Rich text function of the application Space.
Recommendations For Cybozu Garoon versions 3.7.0 through 4.2.5, consider disabling the Rich text function of the Space application until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2255

Affected Products

Cybozu Garoon