FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2016-2228

This CVE name corresponds to:

Entered Topic
2016-02-14 horde -- XSS vulnerabilies

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2016-2228
Phase Assigned(20160206)

Description

Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.

References

Source Reference
MLIST [announce] 20160202 [announce] [SECURITY] Horde Groupware 5.2.12 (final)
MLIST [announce] 20160202 [announce] [SECURITY] Horde Groupware Webmail Edition 5.2.12 (final)
MLIST [oss-security] 20160206 CVE Request: Horde: Two cross-site scripting vulnerabilities
MLIST [oss-security] 20160206 Re: CVE Request: Horde: Two cross-site scripting vulnerabilities
CONFIRM http://bugs.horde.org/ticket/14213
CONFIRM https://github.com/horde/horde/blob/e838d4c800b0d1ecaf8b4cc613fd3af4f994c79c/bundles/webmail/docs/CHANGES
CONFIRM https://github.com/horde/horde/commit/ab07a1b447de34e13983b4d7ceb18b58c3a358d8
DEBIAN DSA-3497
FEDORA FEDORA-2016-3d1183830b
FEDORA FEDORA-2016-5d0e7f15ef