PHPGroupWare has been reported prone to multiple HTML injection vulnerabilities. The issues present themselves due to a lack of sufficient input validation performed on form fields used by PHPGroupWare modules. A malicious attacker may inject arbitrary HTML and script code using these form fields that may be incorporated into dynamically generated web content.
PHPGroupWare has been reported prone to multiple HTML injection vulnerabilities. The issues present themselves due to a lack of sufficient input validation performed on form fields used by PHPGroupWare modules. A malicious attacker may inject arbitrary HTML and script code using these form fields that may be incorporated into dynamically generated web content.