CVE-2012-5565

EUVD-2012-5456
Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
hordeimp
𝑥
≤ 5.0.23
hordeimp
5.0.4
hordeimp
5.0.5
hordeimp
5.0.6
hordeimp
5.0.7
hordeimp
5.0.8
hordeimp
5.0.9
hordeimp
5.0.10
hordeimp
5.0.11
hordeimp
5.0.12
hordeimp
5.0.13
hordeimp
5.0.14
hordeimp
5.0.15
hordeimp
5.0.16
hordeimp
5.0.17
hordeimp
5.0.18
hordeimp
5.0.19
hordeimp
5.0.20
hordeimp
5.0.21
hordeimp
5.0.22
hordegroupware
𝑥
≤ 4.0.8
hordegroupware
4.0
hordegroupware
4.0:rc1
hordegroupware
4.0:rc2
hordegroupware
4.0.1
hordegroupware
4.0.2
hordegroupware
4.0.3
hordegroupware
4.0.4
hordegroupware
4.0.5
hordegroupware
4.0.6
hordegroupware
4.0.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-horde-imp
bookworm
6.2.27-3
fixed
bullseye
6.2.27-2
fixed
sid
6.2.27-3
fixed