CVE-2019-12095 — Cross-site Scripting in Groupware
Severity
8.8HIGHNVD
EPSS
0.4%
top 39.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 24
Latest updateMay 24
Description
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages1 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2019-12095: php-horde - Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other...↗2019