CVE-2009-4363: XSS
TextFilter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message. NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4363?
CVE-2009-4363 has a high severity rating as it allows remote attackers to perform cross-site scripting attacks.
How do I fix CVE-2009-4363?
To fix CVE-2009-4363, upgrade the Horde Application Framework to version 3.3.6 or later, or Horde Groupware to version 1.2.5 or later.
What software is affected by CVE-2009-4363?
CVE-2009-4363 affects multiple versions of the Horde Application Framework and Horde Groupware up to specified versions.
What kind of attack does CVE-2009-4363 allow?
CVE-2009-4363 allows remote attackers to exploit cross-site scripting (XSS) vulnerabilities using data: URIs.
Who can exploit CVE-2009-4363?
Any remote attacker can exploit CVE-2009-4363 if they can inject malicious data: URIs into web pages served by the affected Horde applications.