CVE-2013-6365: CSRF
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2013-6365?
CVE-2013-6365 is a vulnerability in Horde Groupware Web mail 5.1.2 that allows CSRF attacks to change permissions.
How severe is CVE-2013-6365?
CVE-2013-6365 has a severity rating of 5.3 (medium).
What software versions are affected by CVE-2013-6365?
Versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, and 5.2.23+debian0-6 of php-horde and versions 4.2.25-1, 4.2.29-2, and 4.2.29-3 of php-horde-kronolith are affected. Also, Horde Groupware Web mail version 5.1.2, Opensuse versions 13.1 and 13.2, and Debian Linux versions 8.0, 9.0, and 10.0 are affected.
How can I fix CVE-2013-6365?
To fix CVE-2013-6365, upgrade php-horde to versions 5.2.20+debian0-1+deb10u2, 5.2.23+debian0-5, or 5.2.23+debian0-6, upgrade php-horde-kronolith to versions 4.2.25-1, 4.2.29-2, or 4.2.29-3, or upgrade Horde Groupware Web mail to a version that is not affected. Also, make sure to keep your opensuse or Debian Linux system up to date.
Where can I find more information about CVE-2013-6365?
You can find more information about CVE-2013-6365 on the following references: [reference 1](http://archives.neohapsis.com/archives/bugtraq/2013-11/0013.html), [reference 2](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-6365), [reference 3](https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-6365).