The Horde team reports:
Thanks to Naumann IT Security Consulting for reporting the XSS vulnerability. Thanks to Secunia for releasing an advisory for the new CSRF protection in the preference interface The major changes compared to Horde version 3.3.8 are: * Fixed XSS vulnerability in util/icon_browser.php. * Protected preference forms against CSRF attacks. [source]
Thanks to Naumann IT Security Consulting for reporting the XSS vulnerability.
Thanks to Secunia for releasing an advisory for the new CSRF protection in the preference interface
The major changes compared to Horde version 3.3.8 are:
* Fixed XSS vulnerability in util/icon_browser.php.
* Protected preference forms against CSRF attacks.
Copyright © 2003-2005 Jacques Vidrine and contributors. Please see the source of this document for full copyright information.