PT-2012-6359 · Horde+1 · Horde3-Imp+4

Jan Lieskovsky

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2012-0791

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions horde3-dimp versions not specified horde3-imp versions not specified Horde IMP versions prior to 5.0.18 Horde Groupware Webmail Edition versions prior to 4.0.6
Description The issue allows remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities, potentially leading to a breach of protected information integrity. The exploitation can be carried out remotely. Vulnerable parameters include composeCache, rtemode, filename *, formname, and IMAP mailbox names.
Recommendations For horde3-dimp, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For horde3-imp, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Horde IMP versions prior to 5.0.18, update to version 5.0.18 or later. For Horde Groupware Webmail Edition versions prior to 4.0.6, update to version 4.0.6 or later. As a temporary workaround, consider restricting access to the compose page and contacts popup window until a patch is available. Avoid using the vulnerable parameters composeCache, rtemode, filename *, and formname in the affected API endpoints until the issue is resolved.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05412
BDU:2015-05413
CVE-2012-0791
DSA-2485-1
OPENSUSE-SU-2012_0287-1
OPENSUSE-SU-2024:10191-1

Affected Products

Horde Groupware Webmail Edition
Horde Imp
Suse
Horde3-Dimp
Horde3-Imp