CVE-2016-1216: XSS
Published Apr 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.
Affected Software
1 affected component
Cybozu Garoon<=4.2.1
Event History
Apr 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1216?
CVE-2016-1216 has a medium severity rating due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2016-1216?
To fix CVE-2016-1216, upgrade Cybozu Garoon to version 4.2.2 or later.
3
What is the impact of CVE-2016-1216?
The impact of CVE-2016-1216 includes the possibility of an unauthorized user executing malicious scripts in a victim's browser.
4
Which versions of Cybozu Garoon are affected by CVE-2016-1216?
CVE-2016-1216 affects Cybozu Garoon versions prior to 4.2.2.
5
Is there a workaround for CVE-2016-1216?
There is no known workaround for CVE-2016-1216, so upgrading the software is recommended.