CVE-2012-0791: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0791?
CVE-2012-0791 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-0791?
To fix CVE-2012-0791, upgrade to Horde IMP version 5.0.18 or higher and Horde Groupware Webmail Edition version 4.0.6 or higher.
What types of attacks are possible due to CVE-2012-0791?
CVE-2012-0791 allows attackers to inject arbitrary web scripts or HTML, which can lead to phishing or session hijacking attacks.
Which versions of Horde are affected by CVE-2012-0791?
CVE-2012-0791 affects Horde IMP versions prior to 5.0.18 and Horde Groupware Webmail Edition versions prior to 4.0.6.
Can I identify if my system is affected by CVE-2012-0791?
Yes, if you are running any version of Horde IMP earlier than 5.0.18 or Horde Groupware Webmail Edition earlier than 4.0.6, your system is vulnerable.