Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Mrubinsk

#49481de 56,330
5.4CVSS total
Vulnerabilidades · 1
PT-2017-14634
5.4
2017-11-20
Horde · Horde Groupware · CVE-2017-16908
**Name of the Vulnerable Software and Affected Versions** Horde Groupware version 5.2.19 **Description** The issue allows for XSS via the `Name` field during the creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CSRF protection mechanism can then be bypassed. **Recommendations** For Horde Groupware version 5.2.19, update to a version that fixes this issue to prevent potential exploitation.