CVE-2016-1217: XSS
Published Apr 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.
Affected Software
1 affected component
Cybozu Garoon<=4.2.1
Event History
Apr 20, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1217?
CVE-2016-1217 is classified as a medium-severity cross-site scripting vulnerability.
2
How do I fix CVE-2016-1217?
To fix CVE-2016-1217, upgrade Cybozu Garoon to version 4.2.2 or later.
3
Which versions of Cybozu Garoon are affected by CVE-2016-1217?
CVE-2016-1217 affects Cybozu Garoon versions prior to 4.2.2.
4
What type of vulnerability is CVE-2016-1217?
CVE-2016-1217 is a cross-site scripting (XSS) vulnerability.
5
How can CVE-2016-1217 impact users?
CVE-2016-1217 can allow attackers to inject malicious scripts that can execute in users' browsers.