Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities
17 Dec. 2012
Summary
Multiple Horde products including Groupware Webmail Edition, Groupware, and Kronolith are prone to multiple unspecified HTML-injection vulnerabilities because they fail to properly sanitize user-supplied input.
Horde Groupware, Horde Groupware Webmail and Kronolith is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.