CVE-2024-31401: Cybozu Garoon

Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

Affected products

  • Cybozu Garoon: from 5.5.0, before 6.0.0 (fixed in 6.0.0)

Published 2024-06-11. Last modified 2026-06-17.