CVE-2017-16907

In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:horde:groupware:5.2.19:*:*:*:*:*:*:*
cpe:2.3:a:horde:groupware:5.2.21:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-20 20:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-16907

Mitre link : CVE-2017-16907

CVE.ORG link : CVE-2017-16907


JSON object : View

Products Affected

horde

  • groupware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')