Impact
Cybozu Garoon contains a cross‑site scripting flaw that can trigger arbitrary script execution in the web browser of any authenticated user. The vulnerability results from inadequate sanitization of user input, enabling attackers to inject malicious JavaScript. An affected user could experience session hijacking, credential theft, or phishing while interacting with the application.
Affected Systems
The flaw targets Cybozu Garoon, a collaborative platform for email, calendar, and task management. No specific product versions are listed, so any installation of this product may be vulnerable; organizations should verify their environment for exposure.
Risk and Exploitability
The base CVSS score is 6.0, indicating moderate severity, and the vulnerability is not listed in CISA’s KEV catalog, implying limited known exploitation. EPSS is not reported. The likely attack vector requires a victim to be logged into the application; an attacker could supply a crafted URL or embed malicious code through a form that stores data for later use. Consequently, exploitation is possible but not trivial, presenting a significant risk to businesses that use Cybozu Garoon.
OpenCVE Enrichment