Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j8r-p393-w37g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79

Связанные уязвимости

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.

debian
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Hord ...

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79