Cross-Site Scripting Vulnerabilities in Horde IMP by Horde
CVE-2009-0930
Currently unrated
What is CVE-2009-0930?
Horde IMP is susceptible to multiple Cross-Site Scripting (XSS) vulnerabilities that permit remote attackers to inject arbitrary web scripts or HTML into the application. This issue arises from insufficient input validation in several components, specifically 'smime.php', 'pgp.php', and 'message.php', potentially leading to unauthorized actions in the context of impacted users.