PT-2009-3517 · Horde · Horde Groupware+1

Published

2009-03-17

·

Updated

2009-03-18

·

CVE-2009-0931

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Horde versions prior to 3.2.4 Horde versions prior to 3.3.3 Horde Groupware versions prior to 1.1.5
Description A cross-site scripting (XSS) issue exists in the tag cloud search script, allowing remote attackers to inject arbitrary web script or HTML. This could potentially lead to unauthorized actions on behalf of the user.
Recommendations For Horde versions prior to 3.2.4, update to version 3.2.4 or later. For Horde versions prior to 3.3.3, update to version 3.3.3 or later. For Horde Groupware versions prior to 1.1.5, update to version 1.1.5 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0931

Affected Products

Horde
Horde Groupware