CVE-2016-6191
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.
Affected (1)
References (6)
Source: cve@mitre.org
Mailing ListPatchVDB Entry
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Timeline
No history available yet.