VYPR

Groupware Webmail Edition

by Horde (software)

Source repositories

CVEs (43)

  • CVE-2020-8518CriFeb 17, 2020
    risk 0.72cvss 9.8epss 0.72

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

  • CVE-2019-9858HigMay 29, 2019
    risk 0.62cvss 8.8epss 0.19

    Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes the functions getImage() and…

  • CVE-2022-30287HigJul 28, 2022
    risk 0.58cvss 8.0epss 0.71

    Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

  • CVE-2019-12095HigOct 24, 2019
    risk 0.57cvss 8.8epss 0.01

    Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

  • CVE-2013-6364HigNov 5, 2019
    risk 0.53cvss 8.8epss 0.02

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

  • CVE-2020-8866MedMar 23, 2020
    risk 0.46cvss 6.5epss 0.10

    This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within add.php. The issue results from the lack of proper…

  • CVE-2013-6275MedNov 5, 2019
    risk 0.45cvss 6.5epss 0.02

    Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

  • CVE-2020-8865MedMar 23, 2020
    risk 0.44cvss 6.3epss 0.07

    This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template]…

  • CVE-2021-26929MedFeb 14, 2021
    risk 0.43cvss 6.1epss 0.05

    An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in…

  • CVE-2020-8034MedMay 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access…

  • CVE-2020-8035MedMay 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them…

  • CVE-2019-12094MedOct 24, 2019
    risk 0.40cvss 6.1epss 0.02

    Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.

  • CVE-2016-5303MedDec 20, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via crafted data:text/html content in a form (1) action or (2) xlink…

  • CVE-2007-1679MedMar 26, 2007
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in (1) imp/search.php and (2) ingo/rule.php. NOTE: this issue has been disputed by the vendor,…

  • CVE-2016-2228MedApr 13, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated…

  • CVE-2015-8807MedApr 13, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web…

  • CVE-2013-6365MedNov 5, 2019
    risk 0.28cvss 5.3epss 0.01

    Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

  • CVE-2012-0209Sep 25, 2012
    risk 0.09cvss epss 0.72

    Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers…

  • CVE-2015-7984Nov 19, 2015
    risk 0.03cvss epss 0.04

    Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1)…

  • CVE-2010-3695Mar 31, 2011
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the…

Page 1 of 3