PT-2004-3630 · Horde · Horde Application Framework
Published
2004-12-31
·
Updated
2017-07-29
·
CVE-2004-2741
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Horde Application Framework version 2.2.6
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the "help window" (help.php) that allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
module, topic, or module parameters.Recommendations
For Horde Application Framework version 2.2.6, consider disabling the "help window" (help.php) until a patch is available to prevent exploitation. Restrict access to the vulnerable parameters
module, topic, to minimize the risk of XSS attacks.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horde Application Framework