PT-2004-1682 · Horde · Horde Imp
Published
2004-06-23
·
Updated
2017-07-11
·
CVE-2004-0584
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Horde IMP versions 3.2.3 and earlier
Description
The issue is related to improper input validation, which allows remote attackers to execute arbitrary script as other users via script or HTML in an e-mail message, possibly triggering a cross-site scripting (XSS) vulnerability.
Recommendations
For Horde IMP versions 3.2.3 and earlier, apply the security fix to properly validate input and prevent the execution of arbitrary scripts.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Horde Imp