Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-16908

In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 63.2%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2017-16908
  • Horde » Groupware » Version: 5.2.19
    cpe:2.3:a:horde:groupware:5.2.19


Contact Us

Shodan ® - All rights reserved