CVE-2014-4946: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) a mailbox name in the dynamic mailbox view.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4946?
CVE-2014-4946 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2014-4946?
To fix CVE-2014-4946, upgrade Horde Internet Mail Program (IMP) to version 6.1.8 or later and ensure Horde Groupware Webmail Edition is updated to version 5.1.5 or later.
What types of software are affected by CVE-2014-4946?
CVE-2014-4946 affects Horde Internet Mail Program (IMP) versions prior to 6.1.8 and Horde Groupware Webmail Edition versions before 5.1.5.
Can CVE-2014-4946 lead to data compromise?
Yes, CVE-2014-4946 can enable attackers to inject arbitrary web scripts, potentially leading to data compromise.
Are there any known exploits for CVE-2014-4946?
There are no specific publicly known exploits for CVE-2014-4946, but the XSS vulnerabilities present a significant risk.