CVE-2012-5567: XSS
A cross-site scripting (XSS) flaw was found in the way Kronolith, the Horde calendar application, sanitized content of certain event location parameters passed to month, monthlist and prevmonthlist application fields. A remote attacker could provide a specially-crafted URL that, when visited would lead to arbitrary HTML or webscript execution.
References: [1] http://lists.horde.org/archives/announce/2012/000836.html [2] https://github.com/horde/horde/blob/d3dda2d47fad7eb128a0091e732cded0c2601009/kronolith/docs/CHANGES
Refevant upstream patch: [3] http://git.horde.org/horde-git/-/commit/d865c564beb6e98532880aa51a04a79f3311cd1e
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5567?
CVE-2012-5567 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2012-5567?
To mitigate CVE-2012-5567, upgrade the affected Kronolith application to version 3.0.18 or later.
Which applications are affected by CVE-2012-5567?
CVE-2012-5567 affects Kronolith versions prior to 3.0.18 and specific versions of Horde Groupware Webmail Edition.
What type of vulnerability is CVE-2012-5567?
CVE-2012-5567 is a cross-site scripting (XSS) vulnerability.
Can CVE-2012-5567 be exploited remotely?
Yes, a remote attacker can exploit CVE-2012-5567 by using a specially-crafted URL.