CVE Published: 28/08/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: jpcert |
Vendor: Cybozu, Inc. |
Product: Cybozu Garoon Status : PUBLISHED
CVE-2017-2255 Description
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".