CVE-2021-20628: XSS
Published Mar 18, 2021
·Updated
Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this vulnerability occurs only when using Mozilla Firefox.
Affected Software
2 affected components
Cybozu Office>=10.0.0<=10.8.4
Mozilla Firefox
Event History
Mar 18, 2021
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20628?
CVE-2021-20628 is a cross-site scripting vulnerability in the Address Book of Cybozu Office version 10.0.0 to 10.8.4.
2
How does CVE-2021-20628 work?
CVE-2021-20628 allows remote attackers to inject an arbitrary script via unspecified vectors when using Mozilla Firefox.
3
What is the severity of CVE-2021-20628?
CVE-2021-20628 has a severity score of 6.1, which is considered medium.
4
Which software versions are affected by CVE-2021-20628?
Versions 10.0.0 to 10.8.4 of Cybozu Office are affected by CVE-2021-20628.
5
How can I fix CVE-2021-20628?
To fix CVE-2021-20628, it is recommended to update Cybozu Office to a version beyond 10.8.4.