CVE-2017-16906: XSS
Published Nov 20, 2017
·Updated
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.
Affected Software
1 affected component
Horde Groupware Webmail Edition>=5.2.19<=5.2.22
Remediation
Event History
Nov 20, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-16906?
CVE-2017-16906 is a vulnerability in Horde Groupware 5.2.19-5.2.22 that allows for XSS via the URL field in a "Calendar -> New Event" action.
2
What is the severity of CVE-2017-16906?
CVE-2017-16906 has a severity rating of medium.
3
How does CVE-2017-16906 affect Horde Groupware?
CVE-2017-16906 affects Horde Groupware versions 5.2.19-5.2.22.
4
How can I fix CVE-2017-16906?
To fix CVE-2017-16906, update Horde Groupware to a version beyond 5.2.22.
5
Where can I find more information about CVE-2017-16906?
More information about CVE-2017-16906 can be found at the following references: [link1], [link2], [link3].