ZeroHour

CVE-2017-2255

CVSS 3.0
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".

Vendors
cybozu
Products
garoon
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.