First published: Wed Apr 13 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Horde Groupware Webmail Edition | =5.2.11 | |
Horde Groupware Webmail Edition | =5.2.11 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8807 has a medium severity level, allowing attackers to exploit the XSS vulnerability for malicious purposes.
Fix CVE-2015-8807 by upgrading to Horde Groupware versions 5.2.12 or higher.
Horde Groupware versions before 5.2.12, including 5.2.11, are affected by CVE-2015-8807.
CVE-2015-8807 is a cross-site scripting (XSS) vulnerability.
CVE-2015-8807 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.