Several cross-site scripting vulnerabilities have been reported for moregroupware. The vulnerability exists due to insufficient sanitization of user-supplied data. An attacker could exploit these issues by enticing a web user to a malicious link which contains hostile HTML or script code. Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks.
Several cross-site scripting vulnerabilities have been reported for moregroupware. The vulnerability exists due to insufficient sanitization of user-supplied data. An attacker could exploit these issues by enticing a web user to a malicious link which contains hostile HTML or script code. Exploitation could permit an attacker to steal cookie-based authentication credentials or launch other attacks.