CVE-2012-3413 describes a cross-site scripting (XSS) vulnerability in the HTMLQuoteColorer::process function within KDE PIM versions 4.6 through 4.8. This flaw allows remote attackers to inject arbitrary web script or HTML into a user's email by failing to disable JavaScript, Java, and Plugins. With a CVSS score of 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N), exploitation requires medium attack complexity and could lead to information disclosure or defacement, but not confidentiality, integrity, or availability compromise. There is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, nor significant community discussion or media coverage, suggesting low current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.6CPE matchmatch criteria | cpe:2.3:a:kde:kde_pim:4.6:*:*:*:*:*:*:* | ||
4.8CPE matchmatch criteria | cpe:2.3:a:kde:kde_pim:4.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.