CVE-2016-6191: XSS
Published Feb 17, 2017
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.
Affected Software
1 affected component
alinto SOGo<=3.1.2
Remediation
Patch Available
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6191?
CVE-2016-6191 is classified as a critical cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-6191?
To fix CVE-2016-6191, upgrade SOGo to version 3.1.3 or later.
3
What fields are vulnerable in CVE-2016-6191?
The vulnerable fields in CVE-2016-6191 include Description, Location, URL, and Title.
4
Can CVE-2016-6191 lead to remote attacks?
Yes, CVE-2016-6191 allows remote attackers to inject arbitrary web scripts or HTML.
5
Which versions of SOGo are affected by CVE-2016-6191?
CVE-2016-6191 affects SOGo versions up to and including 3.1.2.