Description
|
|
Multiple vulnerabilities were identified in Horde IMP, which may be exploited by attackers to inject malicious HTML code. These flaws are due to input validation errors when handling UTF-16 encoded attachments or displaying specially crafted attachments containing malicious HTML/JavaScript tags, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|