VYPR
Unrated severityNVD Advisory· Published Oct 13, 2021· Updated Aug 3, 2024

CVE-2021-20797

CVE-2021-20797

Description

Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site script inclusion in Cybozu Remote Service 3.1.8 management screen allows authenticated attackers to obtain stored information when using Mozilla Firefox.

Vulnerability

CVE-2021-20797 is a cross-site script inclusion vulnerability (CWE-829) in the management screen of Cybozu Remote Service version 3.1.8. The issue occurs only when the product is accessed using Mozilla Firefox. An authenticated attacker can exploit this flaw to include a script from the management screen, leading to unintended information disclosure [1][2].

Exploitation

An attacker with low-privileged authentication to the Cybozu Remote Service can craft a malicious page or link. When another authenticated user views this content in Mozilla Firefox, the attacker’s script includes a resource from the management screen, causing the victim’s browser to send sensitive data to the attacker. User interaction is required, and the attack is performed over the network [1].

Impact

Successful exploitation allows the attacker to obtain information stored in the product. The CVSS v3 base score is 5.4 (Medium), with low confidentiality and low integrity impact, and no impact on availability. The scope is changed, meaning the compromise can affect resources beyond the vulnerable component [1].

Mitigation

The vulnerability is fixed in Cybozu Remote Service version 4.0.0, released on 2021-09-29 [2]. Users running version 3.1.8 should upgrade to 4.0.0 or later. No workaround is documented. The affected version is limited to 3.1.8; later versions (3.1.9) are not affected [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.