CVE-2020-5564: XSS
Published Apr 28, 2020
·Updated
Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the application 'E-mail'.
Affected Software
1 affected component
Cybozu Garoon>=4.0.0<=4.10.3
Event History
Apr 28, 2020
CVE Published
via MITRE·03:15 AM
Data Sourced
via MITRE·03:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5564?
CVE-2020-5564 has a severity rating associated with cross-site scripting vulnerabilities, allowing for significant impact if exploited.
2
How do I fix CVE-2020-5564?
To fix CVE-2020-5564, update Cybozu Garoon to a version later than 4.10.3.
3
What versions are affected by CVE-2020-5564?
CVE-2020-5564 affects Cybozu Garoon versions from 4.0.0 to 4.10.3.
4
Can CVE-2020-5564 be exploited remotely?
Yes, CVE-2020-5564 can be exploited remotely by attackers through the 'E-mail' application.
5
What type of vulnerability is CVE-2020-5564?
CVE-2020-5564 is classified as a cross-site scripting (XSS) vulnerability.