Vulnerability Details CVE-2004-2574
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.033
EPSS Ranking 86.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2004-2574
-
cpe:2.3:a:phpgroupware:phpgroupware:*
-
cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.000
-
cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.002
-
cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.003