Cross-Site Scripting Vulnerability in Cybozu Garoon
CVE-2026-57279
6MEDIUM
What is CVE-2026-57279?
Cybozu Garoon is susceptible to a cross-site scripting vulnerability where an attacker can potentially execute arbitrary scripts in the web browser of a user logged into the application. If successfully exploited, this vulnerability could lead to unauthorized actions being performed within the web environment, compromising user safety and data integrity. It is crucial for users and administrators of Cybozu Garoon to be aware of this vulnerability, assess their exposure, and implement appropriate security measures to mitigate risks.
Affected Version(s)
Cybozu Garoon 6.17.0 <= 6.17.1
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
