CVE-2021-20797: XSS
Published Oct 13, 2021
·Updated
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.
Affected Software
1 affected component
Cybozu Remote Service Manager=3.1.8
Event History
Oct 13, 2021
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-20797.
2
What is the severity of CVE-2021-20797?
The severity of CVE-2021-20797 is medium with a score of 5.4.
3
What is the affected software for CVE-2021-20797?
The affected software for CVE-2021-20797 is Cybozu Remote Service Manager 3.1.8.
4
How can an attacker exploit this vulnerability?
A remote authenticated attacker can exploit this vulnerability to obtain the information stored in the product.
5
Is this vulnerability specific to a certain web browser?
Yes, this vulnerability occurs only when using Mozilla Firefox.