Описание
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 2.22.5+debian0-1 |
| bionic | not-affected | 2.22.5+debian0-1 |
| cosmic | not-affected | 2.22.5+debian0-1 |
| devel | not-affected | 2.22.5+debian0-1 |
| disco | not-affected | 2.22.5+debian0-1 |
| esm-apps/bionic | not-affected | 2.22.5+debian0-1 |
| esm-apps/xenial | not-affected | 2.22.5+debian0-1 |
| esm-infra-legacy/trusty | released | 2.11.1-2ubuntu0.1~esm1 |
| precise | DNE | |
| precise/esm | DNE |
Показывать по
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number ...
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
EPSS
4.3 Medium
CVSS2
6.1 Medium
CVSS3