CVE-2010-4778: XSS
Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field in a fetchmailprefssave action, related to the Fetchmail configuration, a different issue than CVE-2010-3695. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4778?
CVE-2010-4778 has a medium severity rating due to its potential for remote code execution via cross-site scripting (XSS).
How do I fix CVE-2010-4778?
To fix CVE-2010-4778, upgrade Horde IMP to version 4.3.8 or later, or Horde Groupware Webmail Edition to version 1.2.7 or later.
What are the affected versions of Horde IMP for CVE-2010-4778?
Affected versions of Horde IMP include 2.0 through 4.3.7.
What types of attacks are possible due to CVE-2010-4778?
CVE-2010-4778 allows attackers to inject arbitrary web scripts or HTML, leading to potential phishing or data theft.
Is there a patch available for CVE-2010-4778?
Yes, patches are included in the updated versions of Horde IMP and Horde Groupware that resolve the vulnerabilities.