CVE-2016-1150: XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1150?
CVE-2016-1150 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-1150?
To mitigate CVE-2016-1150, users should upgrade to Cybozu Office version 10.4.0 or later as it includes patches for this vulnerability.
Which versions are affected by CVE-2016-1150?
CVE-2016-1150 affects Cybozu Office versions from 9.0.0 through 10.3.0.
What type of attack does CVE-2016-1150 facilitate?
CVE-2016-1150 allows remote attackers to inject arbitrary web scripts or HTML, leading to cross-site scripting attacks.
Is CVE-2016-1150 related to other vulnerabilities?
Yes, CVE-2016-1150 is a different vulnerability from CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.