{"id":"CVE-2017-16908","details":"In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.","modified":"2026-07-08T11:47:40.370581Z","published":"2017-11-20T20:29:00.480Z","references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00048.html"},{"type":"REPORT","url":"http://code610.blogspot.com/2017/11/rce-via-xss-horde-5219.html"},{"type":"FIX","url":"https://github.com/horde/kronolith/commit/39f740068ad21618f6f70b6e37855c61cadbd716"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/horde/groupware","events":[{"introduced":"861c2461b4c16a64383cfe4daa89eba79dff541a"},{"last_affected":"861c2461b4c16a64383cfe4daa89eba79dff541a"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:horde:groupware:5.2.19:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.2.19"},{"last_affected":"5.2.19"}]}}],"versions":["5.2.19","v5.2.19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16908.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/horde/horde","events":[{"introduced":"801083b02b92b8ba6710471253ecf4b36943c80d"},{"last_affected":"801083b02b92b8ba6710471253ecf4b36943c80d"}],"database_specific":{"cpe":"cpe:2.3:a:horde:groupware:5.2.19:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.2.19"},{"last_affected":"5.2.19"}],"source":"CPE_STRING"}}],"versions":["5.2.19","webmail-5.2.19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16908.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/horde/kronolith","events":[{"introduced":"0"},{"fixed":"39f740068ad21618f6f70b6e37855c61cadbd716"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v4.2.24","v4.2.23","v4.2.22","v4.2.21","v4.2.20","v4.2.19","v4.2.18","v4.2.17","v4.2.16","v4.2.15","v4.2.14","v4.2.13","v4.2.12","v4.2.11","v4.2.10","v4.2.9","v4.2.8","v4.2.7","v4.2.6","v4.2.5","v4.2.4","v4.2.3","v4.2.2","v4.2.1","v4.2.0","v4.2.0rc2","v4.2.0rc1","v4.2.0beta2","v4.2.0beta1","v4.2.0alpha2","v4.2.0alpha1","v4.1.4","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.1.0rc1","v4.1.0beta2","v4.1.0beta1","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v4.0.0rc1","v4.0.0beta2","v4.0.0beta1","v3.0.1","v3.0.0","v3.0.0rc2","v3.0.0rc1","v3.0.0beta1","v3.0.0alpha1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16908.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}