6.0.0-alpha14
▾
Tasks
New Task
Search
Photos
Wiki
▾
Tickets
New Ticket
Search
dev.horde.org
Toggle Alerts Log
Help
6/19/25
History
Attachments
Comment
Watch
Download
Comment on [#14926] Horde Webmail - XSS + CSRF to SQLi, RCE, Stealing Emails <= v5.2.22
*
Your Email Address
*
Spam protection
Enter the letters below:
. . __.. .. ..__. |_/ (__ \ /|\ || | | \.__) \/ | \||__\
Comment
> For the record: > * The XSS in the Horde tag cloud widget had already been discovered, > fixed, and released by ourselves with Horde 5.2.21 on April 21, > before the report: > https://lists.horde.org/archives/announce/2019/001278.html Without > this, the whole "attack" is not exploitable. > * Adding bookmarks in Trean is indeed not CSRF protected, but that's > low priority for us, because it's a non-destructive action. > * GETting IMAP messages from IMP is a core functionality of the > webmail client and is hardly to be called a vulnerability. Whether it > would make sense to token-protected such requests is at least > debatable. > * The reporter irresponsibly disclosed his findings, because we were > not willing, nor able to pay him a bounty price upfront. > > Also for the records, these finding have been assigned CVE 2019-12094 > & CVE-2019-12095. > > Conclusion: no Horde installation installed or updated since April > 21st 2019 is vulnerable to this exploit. >
Attachment
Watch this ticket
New Ticket
My Tickets
Search
Query Builder
Reports
Saved Queries
Open Bugs
Bugs waiting for Feedback
Open Bugs in Releases
Open Enhancements
Enhancements waiting for Feedback
Bugs with Patches
Enhancements with Patches
Release Showstoppers
Stalled Tickets
New Tickets
Horde 5 Showstoppers