CVE-2020-8035
MEDIUM6.1EPSS 0.45%php-horde - security update
發布日:2020/5/18修改日:2026/4/28
描述
The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
受影響套件(2)
- Debian/php-hordefrom 0, < 5.2.23+debian0-1
- Debian/php-hordefrom 0, < 5.2.1+debian0-2+deb8u6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |