MEDIUM
horde: XSS vulnerability via data: URIs
Published Dec 21, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.37%
Description
Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message. NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."
Affected products
No data.
Configuration 1
OR
- ≤ 3.3.5
- 2.0
- 2.1
- 2.1.3
- 2.2
- 2.2.1
- 2.2.3
- 2.2.4
- 2.2.4_rc1
- 2.2.5
- 2.2.6
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.1
- 3.1.1
- 3.2
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- ≤ 1.2.4
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.2
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
Configuration 2
OR
- ≤ 1.2.4
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.2
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://bugs.horde.org/ticket/8715 x_refsource_CONFIRMExploit
- http://bugs.horde.org/view.php?actionID=view_file&type=patch&file=0002-Bug-8715-Fix-XSS-vulnerability%5B1%5D.patch&ticket=8715 x_refsource_CONFIRMExploit
- http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.559&r2=1.515.2.589&ty=h x_refsource_CONFIRM
- http://lists.horde.org/archives/announce/2009/000529.html mailing-listx_refsource_MLISTPatch
- http://marc.info/?l=horde-announce&m=126100750018478&w=2 mailing-listx_refsource_MLISTPatch
- http://marc.info/?l=horde-announce&m=126101076422179&w=2 mailing-listx_refsource_MLISTPatch
- http://securitytracker.com/id?1023365 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2009-4363 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=549516 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4331 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-4363
- https://www.cve.org/CVERecord?id=CVE-2009-4363
| Link | Providers | Tags |
|---|---|---|
| http://bugs.horde.org/ticket/8715 | x_refsource_CONFIRMExploit | |
| http://bugs.horde.org/view.php?actionID=view_file&type=patch&file=0002-Bug-8715-Fix-XSS-vulnerability%5B1%5D.patch&ticket=8715 | x_refsource_CONFIRMExploit | |
| http://cvs.horde.org/diff.php/horde/docs/CHANGES?r1=1.515.2.559&r2=1.515.2.589&ty=h | x_refsource_CONFIRM | |
| http://lists.horde.org/archives/announce/2009/000529.html | mailing-listx_refsource_MLISTPatch | |
| http://marc.info/?l=horde-announce&m=126100750018478&w=2 | mailing-listx_refsource_MLISTPatch | |
| http://marc.info/?l=horde-announce&m=126101076422179&w=2 | mailing-listx_refsource_MLISTPatch | |
| http://securitytracker.com/id?1023365 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2009-4363 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=549516 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-4331 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-4363 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-4363 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 21, 2009
Updated Sep 17, 2024
Reserved Dec 21, 2009
Link CVE-2009-4363
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-4331 Assigner mitre
Published Dec 21, 2009
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2009-4331