VYPR
Unrated severityNVD Advisory· Published Oct 13, 2021· Updated Aug 3, 2024

CVE-2021-20799

CVE-2021-20799

Description

Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated cross-site scripting in Cybozu Remote Service management screen allows arbitrary script injection via unspecified vectors.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in the management screen of Cybozu Remote Service versions 3.1.8 to 3.1.9 [1]. An authenticated remote attacker can inject an arbitrary script via unspecified vectors in the management screen interface [2]. The vulnerability is classified as CWE-79 (Cross-site Scripting) [1].

Exploitation

The attacker must be authenticated with at least basic user privileges to the Cybozu Remote Service management screen [2]. The attack requires user interaction from the victim (e.g., clicking a crafted link) [1][2]. The attack complexity is low, as the attacker does not need special network position beyond standard HTTP access [1][2]. CVSS v3 vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (Base Score 5.4) [1][2].

Impact

Successful exploitation allows the attacker to execute arbitrary scripts in the victim's browser within the context of the Cybozu Remote Service management interface [1][2]. This can lead to information disclosure (e.g., stealing session tokens) and partial integrity impact because the attacker can modify displayed content [2]. The CVSS scope is changed, meaning the impact may extend beyond the vulnerable component [1][2].

Mitigation

The vulnerability is fixed in Cybozu Remote Service version 4.0.0, released on 2021-09-29 [2]. Users should upgrade to version 4.0.0 or later [2]. No workaround or partial mitigation is documented in the available references. Affected versions are 3.1.8 and 3.1.9; end-of-life status is not indicated [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.