Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Horde Gollem 跨站脚本漏洞
Vulnerability Description
Horde Groupware Webmail是美国Horde公司的一套基于浏览器的企业级通信套件。Gollem是使用在其中的一个文件管理器。 Horde Gollem 3.0.13之前版本(用在Horde Groupware Webmail Edition 5.2.22版本和其他产品)中存在跨站脚本漏洞。攻击者可借助恶意制作的URL利用该漏洞访问用户Webmail帐户。
CVSS Information
N/A
Vulnerability Type
N/A