Lucene search

K
cve[email protected]CVE-2024-31401
HistoryJun 11, 2024 - 5:15 a.m.

CVE-2024-31401

2024-06-1105:15:53
web.nvd.nist.gov
24
cve-2024-31401
cybozu garoon
cross-site scripting
remote attacker
administrative privilege
arbitrary script

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

Affected configurations

Vulners
Node
cybozucybozu_garoonRange5.0.05.15.2

CNA Affected

[
  {
    "vendor": "Cybozu, Inc.",
    "product": "Cybozu Garoon",
    "versions": [
      {
        "version": "5.0.0 to 5.15.2",
        "status": "affected"
      }
    ]
  }
]

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-31401