CVE-2021-20628

Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this vulnerability occurs only when using Mozilla Firefox.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cybozu:office:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:46

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN45797538/index.html - Third Party Advisory () https://jvn.jp/en/jp/JVN45797538/index.html - Third Party Advisory
References () https://kb.cybozu.support/article/36868/ - Vendor Advisory () https://kb.cybozu.support/article/36868/ - Vendor Advisory

Information

Published : 2021-03-18 01:15

Updated : 2024-11-21 05:46


NVD link : CVE-2021-20628

Mitre link : CVE-2021-20628

CVE.ORG link : CVE-2021-20628


JSON object : View

Products Affected

mozilla

  • firefox

cybozu

  • office
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')