← Back

CVE-2012-5565

nvd nist
Published: Apr 5, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.

Affected (31)

Products: Horde: Imp, Groupware
2 products
Imp
Groupware
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Horde
Up to 5.0.23
Version 5.0.10
Version 5.0.11
Version 5.0.12
Version 5.0.13
Version 5.0.14
Version 5.0.15
Version 5.0.16
Version 5.0.17
Version 5.0.18
Version 5.0.19
Version 5.0.20
Version 5.0.21
Version 5.0.22
Version 5.0.4
Version 5.0.5
Version 5.0.6
Version 5.0.7
Version 5.0.8
Version 5.0.9
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Horde
Up to 4.0.8
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.5
Version 4.0.6
Version 4.0.7
Version 4.0
Version 4.0 rc1
Version 4.0 rc2

Timeline

No history available yet.