Security Advisory

CVE-2017-2255

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-08-28 20:00:00
Last updated 2024-08-05 13:48:04
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".