First published: Thu Oct 24 2019(Updated: )
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Horde Groupware | <=5.2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12094 is a vulnerability in Horde Groupware Webmail Edition through 5.2.22 that allows XSS (cross-site scripting) attacks.
CVE-2019-12094 has a severity rating of medium with a CVSS score of 6.1.
The affected software of CVE-2019-12094 is Horde Groupware Webmail Edition up to version 5.2.22.
To exploit CVE-2019-12094, an attacker can use the admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI to perform a cross-site scripting attack.
Yes, you should update to a version of Horde Groupware Webmail Edition that is higher than 5.2.22 to fix CVE-2019-12094.