Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-54343
HistoryMay 18, 2022 - 12:00 a.m.

Cybozu Garoon Cross-Site Scripting Vulnerability (CNVD-2022-54343)

2022-05-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
cybozu garoon
cross-site scripting
vulnerability
user data
organizational information
html
script code
browser

EPSS

0.001

Percentile

44.7%

Cybozu Garoon is a portal-based OA office system from Cybozu Japan. The system provides portal, E-mail, bookmarks, scheduling, bulletin board, document management, etc. A cross-site scripting vulnerability exists in Cybozu Garoon, which stems from insufficient cleaning of user-supplied data in organizational information. An attacker could use the vulnerability to trick victims into following specially crafted links and executing arbitrary HTML and script code in the context of a vulnerable website in the user’s browser.

EPSS

0.001

Percentile

44.7%

Related for CNVD-2022-54343