CVE-2017-2255: XSS
Published Aug 28, 2017
·Updated
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
Affected Software
15 affected components
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Cybozu Garoon=4.2.3
Cybozu Garoon=4.2.4
Cybozu Garoon=4.2.5
Event History
Aug 28, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2255?
CVE-2017-2255 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2017-2255?
To fix CVE-2017-2255, upgrade to a version of Cybozu Garoon higher than 4.2.5.
3
What versions of Cybozu Garoon are affected by CVE-2017-2255?
CVE-2017-2255 affects Cybozu Garoon versions 3.7.0 to 4.2.5.
4
What type of vulnerability is CVE-2017-2255?
CVE-2017-2255 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2017-2255 be exploited by attackers?
Yes, CVE-2017-2255 can be exploited by attackers to inject arbitrary scripts via the Rich text function in the application.