First published: Mon Nov 20 2017(Updated: )
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | >=5.2.19<=5.2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16906 is a vulnerability in Horde Groupware 5.2.19-5.2.22 that allows for XSS via the URL field in a "Calendar -> New Event" action.
CVE-2017-16906 has a severity rating of medium.
CVE-2017-16906 affects Horde Groupware versions 5.2.19-5.2.22.
To fix CVE-2017-16906, update Horde Groupware to a version beyond 5.2.22.
More information about CVE-2017-16906 can be found at the following references: [link1], [link2], [link3].