4.3
CVSSv2

CVE-2009-4363

Published: 21/12/2009 Updated: 18/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework prior to 3.3.6, Horde Groupware prior to 1.2.5, and Horde Groupware Webmail Edition prior to 1.2.5 does not properly handle data: URIs, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message. NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."

Vulnerable Product Search on Vulmon Subscribe to Product

horde application framework 2.2.4_rc1

horde application framework 2.2.5

horde application framework 2.2.6

horde application framework 2.0

horde application framework 3.0.7

horde application framework 3.1

horde application framework 3.3.4

horde application framework 2.2.4

horde application framework 2.1

horde application framework 2.2

horde application framework 3.0

horde application framework 3.2.2

horde application framework 3.2.1

horde application framework 3.2

horde groupware 1.2.3

horde groupware 1.2

horde groupware 1.1.2

horde application framework

horde application framework 2.1.3

horde application framework 2.2.1

horde application framework 3.3

horde application framework 3.0.6

horde application framework 3.0.9

horde application framework 3.2.4

horde groupware

horde groupware 1.0.3

horde groupware 1.1.3

horde groupware 1.0.4

horde groupware 1.1.5

horde application framework 2.2.3

horde application framework 3.0.1

horde application framework 3.0.2

horde application framework 3.0.3

horde application framework 3.0.4

horde application framework 3.2.3

horde application framework 3.3.3

horde application framework 3.3.2

horde application framework 3.3.1

horde groupware 1.1.1

horde groupware 1.2.1

horde groupware 1.2.2

horde groupware 1.1.4

horde application framework 3.1.1

horde application framework 3.0.8

horde groupware 1.0

horde groupware 1.0.5

horde groupware 1.1

horde groupware 1.0.2

horde groupware 1.0.1

horde groupware 1.0.7

horde groupware 1.0.6

horde groupware 1.1.6

horde groupware 1.0.8

Vendor Advisories

Several vulnerabilities have been found in horde3, the horde web application framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3237 It has been discovered that horde3 is prone to cross-site scripting attacks via crafted number preferences or inline MIME text parts when using text/plain as MIME ...