Arbitrary Web Script Injection Vulnerability in Cybozu Office Customapp Function

Arbitrary Web Script Injection Vulnerability in Cybozu Office Customapp Function

CVE-2016-4865 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.

Learn more about our Cis Benchmark Audit For Microsoft Office.