CVE-2015-8807: XSS
Cross-site scripting (XSS) vulnerability in the renderVarInputnumber function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8807?
CVE-2015-8807 has a medium severity level, allowing attackers to exploit the XSS vulnerability for malicious purposes.
How do I fix CVE-2015-8807?
Fix CVE-2015-8807 by upgrading to Horde Groupware versions 5.2.12 or higher.
Which versions of Horde Groupware are affected by CVE-2015-8807?
Horde Groupware versions before 5.2.12, including 5.2.11, are affected by CVE-2015-8807.
What type of vulnerability is CVE-2015-8807?
CVE-2015-8807 is a cross-site scripting (XSS) vulnerability.
What are the potential impacts of CVE-2015-8807?
CVE-2015-8807 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.