CVE-2012-5565

Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
hordeimp
𝑥
≤ 5.0.23
hordeimp
5.0.4
hordeimp
5.0.5
hordeimp
5.0.6
hordeimp
5.0.7
hordeimp
5.0.8
hordeimp
5.0.9
hordeimp
5.0.10
hordeimp
5.0.11
hordeimp
5.0.12
hordeimp
5.0.13
hordeimp
5.0.14
hordeimp
5.0.15
hordeimp
5.0.16
hordeimp
5.0.17
hordeimp
5.0.18
hordeimp
5.0.19
hordeimp
5.0.20
hordeimp
5.0.21
hordeimp
5.0.22
hordegroupware
𝑥
≤ 4.0.8
hordegroupware
4.0
hordegroupware
4.0:rc1
hordegroupware
4.0:rc2
hordegroupware
4.0.1
hordegroupware
4.0.2
hordegroupware
4.0.3
hordegroupware
4.0.4
hordegroupware
4.0.5
hordegroupware
4.0.6
hordegroupware
4.0.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-horde-imp
bullseye
6.2.27-2
fixed
sid
6.2.27-3
fixed
bookworm
6.2.27-3
fixed