CVE-2016-4906: XSS
Published Jun 9, 2017
·Updated
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.
Affected Software
27 affected components
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Event History
Jun 9, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4906?
CVE-2016-4906 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2016-4906?
To fix CVE-2016-4906, update your Cybozu Garoon software to version 4.2.3 or later.
3
What systems are affected by CVE-2016-4906?
CVE-2016-4906 affects Cybozu Garoon versions 3.0.0 to 4.2.2.
4
What type of vulnerability is CVE-2016-4906?
CVE-2016-4906 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2016-4906 lead to data theft?
Yes, CVE-2016-4906 can potentially allow attackers to inject malicious scripts that may lead to data theft.