VYPR

Trean

by Horde (software)

CVEs (1)

  • CVE-2019-12095Oct 24, 2019
    risk 0.00cvss epss 0.01

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.