CVE-2024-39457: Cybozu Garoon

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.

Affected products

  • Cybozu Garoon: from 6.0.0, before 6.0.2 (fixed in 6.0.2)

Published 2024-07-19. Last modified 2026-06-17.