CVE-2015-7796
MEDIUMCybozu Office 9.0.0-10.3.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
References (6)
Scores
CVSS v3
6.1
EPSS
0.0052
EPSS Percentile
66.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (15)
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
cybozu/office
Timeline
Published
Feb 17, 2016
Tracked Since
Feb 18, 2026