Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8xjp-h5q2-g6vf

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

EPSS

Процентиль: 77%
0.01047
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

debian
почти 20 лет назад

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 ...

EPSS

Процентиль: 77%
0.01047
Низкий