First published: Mon Jul 14 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via an unspecified flag in the basic (1) mailbox or (2) message view.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware Webmail Edition | <=5.1.4 | |
Horde Groupware Webmail Edition | =5.0.0 | |
Horde Groupware Webmail Edition | =5.0.0-rc1 | |
Horde Groupware Webmail Edition | =5.0.1 | |
Horde Groupware Webmail Edition | =5.0.2 | |
Horde Groupware Webmail Edition | =5.0.3 | |
Horde Groupware Webmail Edition | =5.0.4 | |
Horde Groupware Webmail Edition | =5.0.5 | |
Horde Groupware Webmail Edition | =5.1.0 | |
Horde Groupware Webmail Edition | =5.1.0-rc1 | |
Horde Groupware Webmail Edition | =5.1.1 | |
Horde Groupware Webmail Edition | =5.1.2 | |
Horde Groupware Webmail Edition | =5.1.3 | |
Horde IMP | <=6.1.7 | |
Horde IMP | =6.0.0 | |
Horde IMP | =6.0.0-alpha1 | |
Horde IMP | =6.0.0-beta1 | |
Horde IMP | =6.0.0-beta2 | |
Horde IMP | =6.0.0-beta3 | |
Horde IMP | =6.0.0-beta4 | |
Horde IMP | =6.0.0-rc1 | |
Horde IMP | =6.0.1 | |
Horde IMP | =6.0.2 | |
Horde IMP | =6.0.3 | |
Horde IMP | =6.0.4 | |
Horde IMP | =6.0.5 | |
Horde IMP | =6.0.6 | |
Horde IMP | =6.1.0 | |
Horde IMP | =6.1.0-beta1 | |
Horde IMP | =6.1.0-beta2 | |
Horde IMP | =6.1.0-rc1 | |
Horde IMP | =6.1.1 | |
Horde IMP | =6.1.2 | |
Horde IMP | =6.1.3 | |
Horde IMP | =6.1.4 | |
Horde IMP | =6.1.5 | |
Horde IMP | =6.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4945 allows remote attackers to execute arbitrary web scripts or HTML, potentially compromising user data and session integrity.
CVE-2014-4945 affects Horde Groupware Webmail Edition versions prior to 5.1.5, including all versions before 5.1.5.
To mitigate CVE-2014-4945, upgrade to Horde Groupware Webmail Edition version 5.1.5 or later, which addresses the identified vulnerabilities.
Implementing input validation and sanitization processes on user inputs can help reduce the potential impact of CVE-2014-4945.
CVE-2014-4945 is prevalent in the mailbox and message view features of the Horde Internet Mail Program.