CVE-2015-8807: Debian Linux
Medium severity, CVSS 6.1. EPSS: 2.1% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 22 only; version 23 only
- Horde Groupware: version 5.2.11 only
Published 2016-04-13. Last modified 2026-06-17.