CVE-2019-12095Cross-site Scripting in Groupware

Severity
8.8HIGHNVD
EPSS
0.4%
top 39.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 24

Description

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDhorde/groupware5.2.22

🔴Vulnerability Details

3
GHSA
GHSA-35fh-vqwm-xx6m: Horde Trean, as used in Horde Groupware Webmail Edition through 52022-05-24
OSV
CVE-2019-12095: Horde Trean, as used in Horde Groupware Webmail Edition through 52019-10-24
CVEList
CVE-2019-12095: Horde Trean, as used in Horde Groupware Webmail Edition through 52019-10-24

📋Vendor Advisories

1
Debian
CVE-2019-12095: php-horde - Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other...2019