CVE-2012-5566
Summary
| CVE | CVE-2012-5566 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-05 21:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Horde | Groupware | 4.0 | All | webamail | All |
| Application | Horde | Groupware | 4.0 | rc1 | webamail | All |
| Application | Horde | Groupware | 4.0 | rc2 | webamail | All |
| Application | Horde | Groupware | 4.0.1 | All | webamail | All |
| Application | Horde | Groupware | 4.0.2 | All | webamail | All |
| Application | Horde | Groupware | 4.0.3 | All | webamail | All |
| Application | Horde | Groupware | 4.0.4 | All | webamail | All |
| Application | Horde | Groupware | 4.0.5 | All | webamail | All |
| Application | Horde | Groupware | 4.0.6 | All | webamail | All |
| Application | Horde | Groupware | All | All | webamail | All |
| Application | Horde | Kronolith H4 | 3.0 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0 | alpha1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | beta1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | rc1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | rc2 | All | All |
| Application | Horde | Kronolith H4 | 3.0.1 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.10 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.11 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.12 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.13 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.14 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.15 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.2 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.3 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.4 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.5 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.6 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.7 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.8 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.9 | All | All | All |
| Application | Horde | Kronolith H4 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Horde Groupware Input Validation Flaw in Calendar Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [announce] Horde Groupware Webmail Edition 4.0.8 (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | Vendor Advisory |
| www.osvdb.org/82382 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/82371 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - CVE Request -- kronolith: Two sets (3.0.17 && 3.0.18) of XSS flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| horde/CHANGES at master · horde/horde · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| Tickets :: [#11189] XSS vulnerability in Tasks view | af854a3a-2127-422b-91ae-364da2661108 | bugs.horde.org | |
| openSUSE-SU-2012:1625-1: moderate: horde4-kronolith | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-security - Re: CVE Request -- kronolith: Two sets (3.0.17 && 3.0.18) of XSS flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Horde :: Log in | af854a3a-2127-422b-91ae-364da2661108 | git.horde.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.