Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote malicious users to inject arbitrary web script or HTML via the url parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
horde groupware 1.0.5 |
||
horde groupware webmail edition 1.0.6 |