CVE-2021-20799: XSS
Published Oct 13, 2021
·Updated
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
Affected Software
2 affected components
Cybozu Remote Service Manager=3.1.8
Cybozu Remote Service Manager=3.1.9
Event History
Oct 13, 2021
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20799?
CVE-2021-20799 is a cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
3
What is the severity of CVE-2021-20799?
CVE-2021-20799 has a severity rating of medium with a CVSS score of 5.4.
4
Which software versions are affected by CVE-2021-20799?
Cybozu Remote Service versions 3.1.8 to 3.1.9 are affected by CVE-2021-20799.
5
Is there a fix for CVE-2021-20799?
Yes, please refer to the official documentation for steps on how to fix CVE-2021-20799.