Debian Security Advisory 1560-1 – “The-0utl4w” discovered that the Kronolith, calendar component for the Horde Framework, didn’t properly sanitize URL input, leading to a cross-site scripting vulnerability in the add event screen.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65868/dsa-1560-1.txt
Source: https://packetstormsecurity.com/files/65868/Debian-Linux-Security-Advisory-1560-1.html

