CVE-2012-5567
Summary
| CVE | CVE-2012-5567 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-05 21:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Horde | Groupware | 4.0 | All | webamail | All |
| Application | Horde | Groupware | 4.0 | rc1 | webamail | All |
| Application | Horde | Groupware | 4.0 | rc2 | webamail | All |
| Application | Horde | Groupware | 4.0.1 | All | webamail | All |
| Application | Horde | Groupware | 4.0.2 | All | webamail | All |
| Application | Horde | Groupware | 4.0.3 | All | webamail | All |
| Application | Horde | Groupware | 4.0.4 | All | webamail | All |
| Application | Horde | Groupware | 4.0.5 | All | webamail | All |
| Application | Horde | Groupware | 4.0.6 | All | webamail | All |
| Application | Horde | Groupware | 4.0.7 | All | webamail | All |
| Application | Horde | Groupware | All | All | webamail | All |
| Application | Horde | Kronolith H4 | 3.0 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0 | alpha1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | beta1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | rc1 | All | All |
| Application | Horde | Kronolith H4 | 3.0 | rc2 | All | All |
| Application | Horde | Kronolith H4 | 3.0.1 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.10 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.11 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.12 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.13 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.14 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.15 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.16 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.2 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.3 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.4 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.5 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.6 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.7 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.8 | All | All | All |
| Application | Horde | Kronolith H4 | 3.0.9 | All | All | All |
| Application | Horde | Kronolith H4 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| horde/CHANGES at d3dda2d47fad7eb128a0091e732cded0c2601009 · horde/horde · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Horde :: Log in | af854a3a-2127-422b-91ae-364da2661108 | git.horde.org | |
| 879684 – (CVE-2012-5567) CVE-2012-5567 kronolith: Multiple XSS flaws in the portal blocks | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [announce] Kronolith H4 (3.0.18) (final) | af854a3a-2127-422b-91ae-364da2661108 | lists.horde.org | |
| Multiple Horde Products Multiple Unspecified HTML Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| oss-security - CVE Request -- kronolith: Two sets (3.0.17 && 3.0.18) of XSS flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| www.osvdb.org/87345 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| openSUSE-SU-2012:1625-1: moderate: horde4-kronolith | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| oss-security - Re: CVE Request -- kronolith: Two sets (3.0.17 && 3.0.18) of XSS flaws | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.