CVE-2015-8807
Published: 13 April 2016
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
From the Ubuntu Security Team
It was discovered that Horde improperly handled certain crafted input. An attacker could use this issue to execute a cross-site scripting (XSS) attack.
Priority
Status
Package | Release | Status |
---|---|---|
php-horde-core Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(2.22.5+debian0-1)
|
bionic |
Not vulnerable
(2.22.5+debian0-1)
|
|
cosmic |
Not vulnerable
(2.22.5+debian0-1)
|
|
disco |
Not vulnerable
(2.22.5+debian0-1)
|
|
precise |
Does not exist
|
|
trusty |
Released
(2.11.1-2ubuntu0.1~esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
upstream |
Released
(2.22.4+debian0-1)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Not vulnerable
(2.22.5+debian0-1)
|
|
yakkety |
Not vulnerable
(2.22.5+debian0-1)
|
|
zesty |
Not vulnerable
(2.22.5+debian0-1)
|
|
Patches: upstream: https://github.com/horde/horde/commit/11d74fa5a22fe626c5e5a010b703cd46a136f253 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.1 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Changed |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |