CVE-2013-6912: XSS
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6912?
CVE-2013-6912 has been classified as a moderate severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2013-6912?
To fix CVE-2013-6912, upgrade to Cybozu Garoon version 3.7.2 or later, which addresses this vulnerability.
Which versions of Cybozu Garoon are affected by CVE-2013-6912?
CVE-2013-6912 affects Cybozu Garoon versions prior to 3.7.2 and specific earlier versions like 2.0 through 3.5.
What type of vulnerability is CVE-2013-6912?
CVE-2013-6912 is a cross-site scripting (XSS) vulnerability, allowing attackers to inject arbitrary web scripts or HTML.
Who is at risk from CVE-2013-6912?
Remote authenticated users of affected versions of Cybozu Garoon using Internet Explorer 6 through 9 are at risk from CVE-2013-6912.