Arbitrary Code Injection Vulnerability in Cybozu Garoon's Space Rich Text Function

Arbitrary Code Injection Vulnerability in Cybozu Garoon's Space Rich Text Function

CVE-2017-2255 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".

Learn more about our Web App Pen Testing.