Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mrubinsk

#47193de 53,634
5.4CVSS total
Vulnerabilidades · 1
PT-2017-14634
5.4
2017-11-20
Horde · Horde Groupware · CVE-2017-16908
**Name of the Vulnerable Software and Affected Versions** Horde Groupware version 5.2.19 **Description** The issue allows for XSS via the `Name` field during the creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CSRF protection mechanism can then be bypassed. **Recommendations** For Horde Groupware version 5.2.19, update to a version that fixes this issue to prevent potential exploitation.