CVE-2012-0909: XSS
Cross-site scripting (XSS) vulnerability in HordeForm in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0909?
CVE-2012-0909 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary web scripts or HTML.
How do I fix CVE-2012-0909?
To remediate CVE-2012-0909, upgrade Horde Groupware Webmail Edition to version 4.0.6 or later.
Which versions are affected by CVE-2012-0909?
CVE-2012-0909 affects all versions of Horde Groupware Webmail Edition prior to 4.0.6, including multiple releases from 1.0 to 4.0.4.
What type of vulnerability is CVE-2012-0909?
CVE-2012-0909 is a Cross-Site Scripting (XSS) vulnerability that can lead to the injection of malicious scripts.
What are the implications of CVE-2012-0909?
If exploited, CVE-2012-0909 can compromise user accounts and allow attackers to manipulate or steal user data.