[horde] How horde protects from XSS Vulnerability?

ANANT S ATHAVALE asa at isac.gov.in
Thu Apr 19 13:02:10 UTC 2018


Dear Team,

Recently we observed that, when a script with src like <script  
src=......></script> is in HTML body of the message, horde/imp  did  
not execute it and  view source confirmed that, the script was  
truncated.

I assume that, Horde has taken care of these XSS vulnerabilties within  
its code.  Just curious.
           सादर धन्यवाद/ Thanks &
Regards          
                  अनंत / Anant
 
------------------------------------------------------------------------------
Confidentiality Notice: This e-mail message, including any attachments, is for
the sole use of the intended recipient(s) and may contain confidential and
privileged information. Any unauthorized review, use, disclosure or
distribution is prohibited. If you are not the intended recipient, please
contact the sender by reply e-mail and destroy all copies of the original
message.
------------------------------------------------------------------------------



More information about the horde mailing list