CVE-2013-6916: XSS
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6916?
CVE-2013-6916 is classified as a cross-site scripting (XSS) vulnerability, which can allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2013-6916?
To fix CVE-2013-6916, upgrade to a version of Cybozu Garoon that is 3.7.2 or later.
Which versions of Cybozu Garoon are affected by CVE-2013-6916?
CVE-2013-6916 affects Cybozu Garoon versions prior to 3.7.2, along with specific 2.0 to 3.5 versions.
Which browsers trigger the vulnerability CVE-2013-6916?
The vulnerability CVE-2013-6916 is triggered when the application is accessed via Internet Explorer 9 or 10, or Google Chrome.
What can attackers achieve with CVE-2013-6916?
Attackers exploiting CVE-2013-6916 can inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.