Cross-site Scripting Flaw in Cybozu Office by Cybozu
CVE-2022-28715

6.1MEDIUM

Key Information:

Vendor

Cybozu

Vendor
CVE Published:
18 August 2022

What is CVE-2022-28715?

A cross-site scripting vulnerability exists in Cybozu Office versions 10.0.0 to 10.8.5, allowing remote attackers to inject arbitrary scripts through certain parameters. This flaw can lead to unauthorized actions initiated by users and potential compromises of sensitive data when malicious scripts are executed in the context of the victim’s browser.

Affected Version(s)

Cybozu Office 10.0.0 to 10.8.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.