CVE-2015-7796: XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7796?
CVE-2015-7796 is classified as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks in affected versions of Cybozu Office.
How do I fix CVE-2015-7796?
To mitigate CVE-2015-7796, upgrade Cybozu Office to version 10.3.1 or later, where the vulnerability has been patched.
Which versions of Cybozu Office are affected by CVE-2015-7796?
CVE-2015-7796 affects Cybozu Office versions 9.0.0 to 10.3.0.
What types of attacks are possible with CVE-2015-7796?
An attacker could exploit CVE-2015-7796 to inject arbitrary web scripts or HTML into the application, potentially leading to unauthorized actions in the user's context.
How can I determine if my installation is vulnerable to CVE-2015-7796?
Check your Cybozu Office version against the affected versions to see if you are running any version from 9.0.0 to 10.3.0.