CVE-2019-5929: XSS
Published May 17, 2019
·Updated
Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via the application 'Memo'.
Affected Software
1 affected component
Cybozu Garoon>=4.0.0<=4.6.3
Event History
May 17, 2019
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5929?
CVE-2019-5929 is considered a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2019-5929?
To fix CVE-2019-5929, upgrade Cybozu Garoon to version 4.6.4 or later.
3
What types of attacks can CVE-2019-5929 facilitate?
CVE-2019-5929 can facilitate cross-site scripting attacks, allowing attackers to inject malicious scripts.
4
What versions of Cybozu Garoon are affected by CVE-2019-5929?
CVE-2019-5929 affects Cybozu Garoon versions 4.0.0 to 4.6.3.
5
Is it safe to use Cybozu Garoon 4.6.3 after CVE-2019-5929 is identified?
No, using Cybozu Garoon 4.6.3 is not safe until it is updated to a version that patches CVE-2019-5929.