CVE-2022-33151: XSS
Published Aug 18, 2022
·Updated
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.
Affected Software
1 affected component
Cybozu Office>=10.0.0<=10.8.5
Event History
Aug 18, 2022
CVE Published
via MITRE·07:14 AM
Data Sourced
via MITRE·07:14 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-33151?
CVE-2022-33151 is a cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5.
2
How does CVE-2022-33151 impact Cybozu Office?
CVE-2022-33151 allows remote attackers to inject an arbitrary script via unspecified vectors in Cybozu Office 10.0.0 to 10.8.5.
3
What is the severity of CVE-2022-33151?
CVE-2022-33151 has a severity of medium, with a CVSS score of 6.1.
4
How can I fix the CVE-2022-33151 vulnerability in Cybozu Office?
To fix the CVE-2022-33151 vulnerability, update Cybozu Office to a version higher than 10.8.5.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-33151?
CVE-2022-33151 is associated with CWE-79, which is a weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').