First published: Wed Aug 18 2021(Updated: )
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | >=4.0.0<=5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20774.
The severity rating for CVE-2021-20774 is 5.4 (Medium).
The vulnerability allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors in certain functions of E-mail.
Cybozu Garoon versions 4.0.0 to 5.5.0 are affected by this vulnerability.
To fix the vulnerability, it is recommended to update Cybozu Garoon to a version beyond 5.5.0.