First published: Tue Nov 05 2019(Updated: )
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | =5.1.2 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/php-horde | 5.2.23+debian0-5 5.2.23+debian0-6 | |
debian/php-horde-turba | 4.2.25-5 4.2.29-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-6364 is high with a severity value of 8.8.
CVE-2013-6364 affects Horde Groupware Webmail Edition by allowing CSRF (Cross-Site Request Forgery) and XSS (Cross-Site Scripting) attacks when saving a search as a virtual address book.
Horde Groupware Webmail Edition version 5.1.2 is affected by CVE-2013-6364.
Yes, there are fixes available for CVE-2013-6364. For the php-horde package, versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, and 5.2.23+debian0-6 are recommended. For the php-horde-turba package, versions 4.2.23-1, 4.2.23-1+deb10u1, 4.2.25-5, and 4.2.29-2 are recommended.
You can find more information about CVE-2013-6364 at the following references: [1] [2] [3]