In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2350-1 php-horde-kronolith security update
EUVD EUVD EUVD-2017-8078 In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:35:21.314Z

Reserved: 2017-11-20T00:00:00

Link: CVE-2017-16908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-20T20:29:00.480

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-16908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses