FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

horde-gollem -- XSS vulnerability

Affected packages
horde-gollem < 1.1.2

Details

VuXML ID e08c596e-cb28-11df-9c1b-0011098ad87f
Discovery 2010-08-21
Entry 2010-09-28

The Horde team reports:

The major changes compared to Gollem version H3 (1.1.1) are:

* Fixed an XSS vulnerability in the file viewer.

References

URL http://article.gmane.org/gmane.comp.horde.announce/523
URL http://bugs.horde.org/ticket/9191
URL http://git.horde.org/diff.php/gollem/docs/CHANGES?rt=horde&r1=1.114.2.55&r2=1.114.2.59&ty=h