First published: Mon Nov 20 2017(Updated: )
In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | =5.2.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16908 is a vulnerability in Horde Groupware 5.2.19 that allows XSS via the Name field during the creation of a new Resource.
CVE-2017-16908 has a severity rating of 5.4, which is considered medium.
CVE-2017-16908 affects Horde Groupware 5.2.19 by allowing an attacker to perform XSS attacks through the Name field when creating a new Resource.
Yes, CVE-2017-16908 can be leveraged for remote code execution after compromising an administrator account, as it bypasses the CSRF protection mechanism.
To fix CVE-2017-16908, it is recommended to update Horde Groupware to a version that includes the necessary security patches.