CVE-2013-0702: XSS
Published Feb 14, 2013
·Updated
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 3.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
13 affected components
Cybozu Garoon=2.0.0
Cybozu Garoon=2.0.1
Cybozu Garoon=2.0.2
Cybozu Garoon=2.0.3
Cybozu Garoon=2.0.4
Cybozu Garoon=2.0.5
Cybozu Garoon=2.0.6
Cybozu Garoon=2.1.0
Cybozu Garoon=2.1.1
Cybozu Garoon=2.1.2
Cybozu Garoon=2.1.3
Cybozu Garoon=2.5.0
Cybozu Garoon=3.5.3
Event History
Feb 14, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0702?
CVE-2013-0702 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2013-0702?
To fix CVE-2013-0702, update your Cybozu Garoon to the latest version, which resolves the XSS vulnerability.
3
Which versions of Cybozu Garoon are affected by CVE-2013-0702?
CVE-2013-0702 affects Cybozu Garoon versions from 2.0.0 to 3.5.3.
4
What type of attack is possible with CVE-2013-0702?
CVE-2013-0702 allows remote attackers to inject arbitrary web scripts or HTML into affected systems.
5
Is user input protected against XSS in Cybozu Garoon versions before the fix of CVE-2013-0702?
No, user input in affected versions of Cybozu Garoon does not adequately protect against XSS attacks.