CVE-2024-31401: XSS
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31401?
CVE-2024-31401 is considered a medium severity vulnerability due to its potential impact on user data integrity.
How do I fix CVE-2024-31401?
To fix CVE-2024-31401, upgrade Cybozu Garoon to version 5.15.3 or later, where this vulnerability has been addressed.
Who is affected by CVE-2024-31401?
CVE-2024-31401 affects users of Cybozu Garoon versions 5.0.0 to 5.15.2 who have administrative privileges.
What type of vulnerability is CVE-2024-31401?
CVE-2024-31401 is a cross-site scripting (XSS) vulnerability that allows an attacker to inject scripts into user browsers.
Can CVE-2024-31401 be exploited remotely?
Yes, CVE-2024-31401 can be exploited remotely by authenticated attackers with administrative privileges.