Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this vulnerability occurs only when using Mozilla Firefox.
References
Link | Resource |
---|---|
https://kb.cybozu.support/article/36868/ | Vendor Advisory |
https://jvn.jp/en/jp/JVN45797538/index.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-03-17 18:15
Updated : 2021-03-23 07:28
NVD link : CVE-2021-20628
Mitre link : CVE-2021-20628
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
cybozu
- office
mozilla
- firefox