CVE-2009-4662
Novell GroupWise <7.03 HP4, <8.0 SP1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter.
References (6)
Scores
EPSS
0.0088
EPSS Percentile
75.2%
Classification
CWE
CWE-79
Status
published
Affected Products (8)
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
n/a/n/a
Timeline
Published
Mar 03, 2010
Tracked Since
Feb 18, 2026