PT-2012-6359 · Horde+1 · Horde3-Imp+4
Jan Lieskovsky
·
Published
1970-01-01
·
Updated
2024-06-15
·
CVE-2012-0791
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
horde3-dimp versions not specified
horde3-imp versions not specified
Horde IMP versions prior to 5.0.18
Horde Groupware Webmail Edition versions prior to 4.0.6
Description
The issue allows remote attackers to exploit multiple cross-site scripting (XSS) vulnerabilities, potentially leading to a breach of protected information integrity. The exploitation can be carried out remotely. Vulnerable parameters include
composeCache, rtemode, filename *, formname, and IMAP mailbox names.Recommendations
For horde3-dimp, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For horde3-imp, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Horde IMP versions prior to 5.0.18, update to version 5.0.18 or later.
For Horde Groupware Webmail Edition versions prior to 4.0.6, update to version 4.0.6 or later.
As a temporary workaround, consider restricting access to the compose page and contacts popup window until a patch is available.
Avoid using the vulnerable parameters
composeCache, rtemode, filename *, and formname in the affected API endpoints until the issue is resolved.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horde Groupware Webmail Edition
Horde Imp
Suse
Horde3-Dimp
Horde3-Imp