Cross-Site Scripting Vulnerabilities in Horde IMP by Horde
CVE-2009-0930

Currently unrated

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
17 March 2009

What is CVE-2009-0930?

Horde IMP is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities that permit remote attackers to inject arbitrary web scripts or HTML into the application. This issue arises from insufficient input validation in several components, specifically 'smime.php', 'pgp.php', and 'message.php', potentially leading to unauthorized actions in the context of impacted users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.