CVE-2016-1215: XSS
Published Apr 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.
Affected Software
1 affected component
Cybozu Garoon<=4.2.1
Event History
Apr 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1215?
CVE-2016-1215 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-1215?
To fix CVE-2016-1215, upgrade Cybozu Garoon to version 4.2.2 or later.
3
What components are affected by CVE-2016-1215?
CVE-2016-1215 affects the 'User details' function in Cybozu Garoon versions prior to 4.2.2.
4
Can CVE-2016-1215 be exploited remotely?
Yes, CVE-2016-1215 can be exploited remotely to execute arbitrary JavaScript code in the context of a victim's browser.
5
What are the potential impacts of CVE-2016-1215?
The potential impacts of CVE-2016-1215 include session hijacking and data theft through drawn-in cross-site scripting attacks.