CVE-2016-1197: XSS
Published Jun 19, 2016
·Updated
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7775.
Affected Software
5 affected components
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Remediation
Patch Available
Event History
Jun 19, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1197?
CVE-2016-1197 is classified as a moderate severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2016-1197?
To mitigate CVE-2016-1197, upgrade Cybozu Garoon to version 4.2.1 or later.
3
What types of attacks can CVE-2016-1197 enable?
CVE-2016-1197 can enable remote attackers to inject arbitrary web scripts or HTML into the application.
4
What versions of Cybozu Garoon are affected by CVE-2016-1197?
CVE-2016-1197 affects Cybozu Garoon versions 4.0.0 through 4.2.0.
5
Is CVE-2016-1197 related to any other vulnerabilities?
CVE-2016-1197 is a different vulnerability than CVE-2015-7775, despite both involving XSS issues.