First published: Tue Nov 05 2019(Updated: )
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | =5.1.2 | |
openSUSE openSUSE | =13.1 | |
openSUSE openSUSE | =13.2 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/php-horde | 5.2.23+debian0-5 5.2.23+debian0-6 | |
debian/php-horde-kronolith | 4.2.29-2 4.2.29-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6365 is a vulnerability in Horde Groupware Web mail 5.1.2 that allows CSRF attacks to change permissions.
CVE-2013-6365 has a severity rating of 5.3 (medium).
Versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, and 5.2.23+debian0-6 of php-horde and versions 4.2.25-1, 4.2.29-2, and 4.2.29-3 of php-horde-kronolith are affected. Also, Horde Groupware Web mail version 5.1.2, Opensuse versions 13.1 and 13.2, and Debian Linux versions 8.0, 9.0, and 10.0 are affected.
To fix CVE-2013-6365, upgrade php-horde to versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, or 5.2.23+debian0-6, upgrade php-horde-kronolith to versions 4.2.25-1, 4.2.29-2, or 4.2.29-3, or upgrade Horde Groupware Web mail to a version that is not affected. Also, make sure to keep your opensuse or Debian Linux system up to date.
You can find more information about CVE-2013-6365 on the following references: [reference 1](http://archives.neohapsis.com/archives/bugtraq/2013-11/0013.html), [reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6365), [reference 3](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6365).