A cross-site scripting vulnerability was found in php-horde application framework. No input validation was put in place while searching via the menu bar.
Created php-horde-horde tracking bugs for this issue: Affects: epel-6 [bug 1304398] Affects: epel-7 [bug 1304399] Affects: fedora-all [bug 1304400]
Upstream bug report: https://bugs.horde.org/ticket/14213 Upstream patch announcement: http://lists.horde.org/archives/announce/2016/001140.html
php-horde-horde-5.2.9-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
php-horde-horde-5.2.9-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
php-horde-horde-5.2.9-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
php-horde-horde-5.2.9-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.