4.3

CVE-2014-4945

Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via an unspecified flag in the basic (1) mailbox or (2) message view.

Data is provided by the National Vulnerability Database (NVD)
HordeGroupware SwEditionwebmail Version <= 5.1.4
HordeGroupware Version5.0.0 SwEditionwebmail
HordeGroupware Version5.0.0 Updaterc1 SwEditionwebmail
HordeGroupware Version5.0.1 SwEditionwebmail
HordeGroupware Version5.0.2 SwEditionwebmail
HordeGroupware Version5.0.3 SwEditionwebmail
HordeGroupware Version5.0.4 SwEditionwebmail
HordeGroupware Version5.0.5 SwEditionwebmail
HordeGroupware Version5.1.0 SwEditionwebmail
HordeGroupware Version5.1.0 Updaterc1 SwEditionwebmail
HordeGroupware Version5.1.1 SwEditionwebmail
HordeGroupware Version5.1.2 SwEditionwebmail
HordeGroupware Version5.1.3 SwEditionwebmail
HordeInternet Mail Program Version <= 6.1.7
HordeInternet Mail Program Version6.0.0
HordeInternet Mail Program Version6.0.0 Updatealpha1
HordeInternet Mail Program Version6.0.0 Updatebeta1
HordeInternet Mail Program Version6.0.0 Updatebeta2
HordeInternet Mail Program Version6.0.0 Updatebeta3
HordeInternet Mail Program Version6.0.0 Updatebeta4
HordeInternet Mail Program Version6.0.0 Updaterc1
HordeInternet Mail Program Version6.0.1
HordeInternet Mail Program Version6.0.2
HordeInternet Mail Program Version6.0.3
HordeInternet Mail Program Version6.0.4
HordeInternet Mail Program Version6.0.5
HordeInternet Mail Program Version6.0.6
HordeInternet Mail Program Version6.1.0
HordeInternet Mail Program Version6.1.0 Updatebeta1
HordeInternet Mail Program Version6.1.0 Updatebeta2
HordeInternet Mail Program Version6.1.0 Updaterc1
HordeInternet Mail Program Version6.1.1
HordeInternet Mail Program Version6.1.2
HordeInternet Mail Program Version6.1.3
HordeInternet Mail Program Version6.1.4
HordeInternet Mail Program Version6.1.5
HordeInternet Mail Program Version6.1.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.52% 0.639
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.