Cross-Site Scripting Vulnerability in Novell GroupWise Product
CVE-2012-0272

Currently unrated

Key Information:

Vendor
Novell
Status
Vendor
CVE Published:
19 September 2012

Summary

The WebAccess component of Novell GroupWise 8.0 is vulnerable to cross-site scripting (XSS), allowing remote attackers to inject arbitrary web scripts or HTML code through the merge parameter. This exploitation can lead to a compromised user experience, unauthorized actions on behalf of users, and potential data leakage. Users and administrators are advised to apply the necessary updates found in Support Pack 3 to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.