First published: Mon Nov 20 2017(Updated: )
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware Webmail Edition | =5.2.19 | |
Horde Groupware Webmail Edition | =5.2.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16907 is a vulnerability in Horde Groupware versions 5.2.19 and 5.2.21 that allows for cross-site scripting (XSS) through the Color field in a Create Task List action.
CVE-2017-16907 has a severity rating of medium with a CVSS score of 5.4.
CVE-2017-16907 affects Horde Groupware versions 5.2.19 and 5.2.21.
To fix CVE-2017-16907, it is recommended to update Horde Groupware to a version that is not affected by the vulnerability.
Additional information about CVE-2017-16907 can be found in the provided references: http://code610.blogspot.com/2017/11/rce-via-xss-horde-5219.html, https://github.com/horde/base/commit/fb2113bbcd04bd4a28c46aad0889fb0a3979a230, https://lists.debian.org/debian-lts-announce/2020/08/msg00046.html.