Unrated severityNVD Advisory· Published May 18, 2020· Updated Aug 4, 2024
CVE-2020-8035
CVE-2020-8035
Description
The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Horde/Horde Groupware Webmail Editiondescription
- Range: <5.2.22
Patches
Vulnerability mechanics
References
3- github.com/horde/base/blob/c00f2fdb222055fb2ccb6d53b5b5240c0a7d2a75/docs/CHANGESmitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2020/05/msg00035.htmlmitremailing-listx_refsource_MLIST
- lists.horde.org/archives/announce/2020/001290.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.