CVE-2013-6364: CSRF
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6364?
The severity of CVE-2013-6364 is high with a severity value of 8.8.
How does CVE-2013-6364 affect Horde Groupware Webmail Edition?
CVE-2013-6364 affects Horde Groupware Webmail Edition by allowing CSRF (Cross-Site Request Forgery) and XSS (Cross-Site Scripting) attacks when saving a search as a virtual address book.
Which versions of Horde Groupware Webmail Edition are affected by CVE-2013-6364?
Horde Groupware Webmail Edition version 5.1.2 is affected by CVE-2013-6364.
Are there any fixes available for CVE-2013-6364?
Yes, there are fixes available for CVE-2013-6364. For the php-horde package, versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, and 5.2.23+debian0-6 are recommended. For the php-horde-turba package, versions 4.2.23-1, 4.2.23-1+deb10u1, 4.2.25-5, and 4.2.29-2 are recommended.
Where can I find more information about CVE-2013-6364?
You can find more information about CVE-2013-6364 at the following references: [1] [2] [3]