Medium severity5.4NVD Advisory· Published Aug 29, 2017· Updated May 13, 2026
CVE-2017-2255
CVE-2017-2255
Description
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
Affected products
16cpe:2.3:a:cybozu:garoon:3.7.0:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:cybozu:garoon:3.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:3.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:3.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:3.7.3:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:3.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:3.7.5:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:cybozu:garoon:4.2.5:*:*:*:*:*:*:*
- Cybozu, Inc./Cybozu Garoonv5Range: 3.7.0 to 4.2.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN63564682/index.htmlnvdThird Party AdvisoryVDB Entry
- support.cybozu.com/ja-jp/article/9746nvdVendor Advisory
News mentions
0No linked articles in our index yet.