CVE-2021-20628

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this vulnerability occurs only when using Mozilla Firefox.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*

History

23 Mar 2021, 14:28

Type Values Removed Values Added
References (MISC) https://kb.cybozu.support/article/36868/ - (MISC) https://kb.cybozu.support/article/36868/ - Vendor Advisory
References (MISC) https://jvn.jp/en/jp/JVN45797538/index.html - (MISC) https://jvn.jp/en/jp/JVN45797538/index.html - Third Party Advisory
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*

18 Mar 2021, 01:28

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-18 01:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-20628

Mitre link : CVE-2021-20628

CVE.ORG link : CVE-2021-20628


JSON object : View

Products Affected

mozilla

  • firefox

cybozu

  • office
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')