PT-2017-14634 · Horde · Horde Groupware

Mrubinsk

·

Published

2017-11-20

·

Updated

2020-08-29

·

CVE-2017-16908

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Horde Groupware version 5.2.19
Description The issue allows for XSS via the Name field during the creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CSRF protection mechanism can then be bypassed.
Recommendations For Horde Groupware version 5.2.19, update to a version that fixes this issue to prevent potential exploitation.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16908
DLA-2350-1

Affected Products

Horde Groupware