CVE-2008-6746Cross-site Scripting in Turba H3

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 44.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDhorde/turba_h32.2+26

🔴Vulnerability Details

1
GHSA
GHSA-jph3-26cr-xxcp: Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 22022-05-17

📋Vendor Advisories

1
Red Hat
turba: XSS issue in the contact view2008-06-13

💬Community

1
Bugzilla
CVE-2008-6746 turba: XSS issue in the contact view2008-06-23