CVE-2019-12094Cross-site Scripting in Groupware

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 25.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 24

Description

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDhorde/groupware5.2.22

🔴Vulnerability Details

3
GHSA
GHSA-wpwg-9p7v-m644: Horde Groupware Webmail Edition through 52022-05-24
CVEList
CVE-2019-12094: Horde Groupware Webmail Edition through 52019-10-24
OSV
CVE-2019-12094: Horde Groupware Webmail Edition through 52019-10-24

📋Vendor Advisories

1
Debian
CVE-2019-12094: php-horde - Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?...2019