MEDIUM🇵🇱 Wersja polska

CVE-2008-2783

CVSS 4.3v2.0pub. 2008-06-19upd. 2026-04-23

Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Horde Groupware

    APP
    Horde
    all versions
  • Horde Groupware Webmail Edition

    APP
    Horde
    all versions
  • Horde Kronolith

    APP
    Horde
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-8518CRITICAL9.8PL ✓same product

RCE w Horde Groupware — wstrzyknięcie kodu PHP przez import CSV

CVE-2022-30287HIGH8.0same product

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker ...

CVE-2013-6364HIGH8.8same product

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

CVE-2019-12095HIGH8.8same product

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as dem...

CVE-2019-9858HIGH8.8same product

Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contain...