DSA-1770 imp4 -- Insufficient input sanitisingID: oval:org.mitre.oval:def:8083 | Date: (C)2009-12-15 (M)2021-06-02 |
Class: PATCH | Family: unix |
Several vulnerabilities have been found in imp4, a webmail component for the horde framework. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that imp4 suffers from a cross-site scripting (XSS) attack via the user field in an IMAP session, which allows attackers to inject arbitrary HTML code. It was discovered that imp4 is prone to several cross-site scripting (XSS) attacks via several vectors in the mail code allowing attackers to inject arbitrary HTML code.