PT-2017-15302 · Cybozu · Cybozu Garoon

Published

2017-08-28

·

Updated

2017-08-30

·

CVE-2017-2256

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cybozu Garoon versions 3.0.0 through 4.2.5
Description A cross-site scripting issue exists, allowing an attacker to inject arbitrary web script or HTML via the Rich text function of the application Memo.
Recommendations For Cybozu Garoon versions 3.0.0 through 4.2.5, consider disabling the Rich text function of the Memo application until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2256

Affected Products

Cybozu Garoon