Cross-Site Scripting Vulnerability in Cybozu Garoon Scheduler
CVE-2022-29513
4.8MEDIUM
What is CVE-2022-29513?
A cross-site scripting vulnerability exists in the Scheduler component of Cybozu Garoon versions 4.10.0 to 5.5.1. This flaw permits remote, authenticated attackers with administrative rights to inject and execute arbitrary scripts. Exploitations of this vulnerability can lead to unauthorized actions, data exposure, and compromise of user sessions. Organizations utilizing affected versions should apply updates to mitigate any potential security risks associated with this vulnerability.
Affected Version(s)
Cybozu Garoon 4.10.0 to 5.5.1