CVE-2017-16907: XSS
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2017-16907 about?
CVE-2017-16907 is a vulnerability in Horde Groupware versions 5.2.19 and 5.2.21 that allows for cross-site scripting (XSS) through the Color field in a Create Task List action.
What is the severity of CVE-2017-16907?
CVE-2017-16907 has a severity rating of medium with a CVSS score of 5.4.
How does CVE-2017-16907 affect Horde Groupware?
CVE-2017-16907 affects Horde Groupware versions 5.2.19 and 5.2.21.
How can I fix CVE-2017-16907?
To fix CVE-2017-16907, it is recommended to update Horde Groupware to a version that is not affected by the vulnerability.
Is there any additional information about CVE-2017-16907?
Additional information about CVE-2017-16907 can be found in the provided references: http://code610.blogspot.com/2017/11/rce-via-xss-horde-5219.html, https://github.com/horde/base/commit/fb2113bbcd04bd4a28c46aad0889fb0a3979a230, https://lists.debian.org/debian-lts-announce/2020/08/msg00046.html.