CVE-2019-12094: XSS
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=updatef&username= or admin/user.php?form=removef&username= or admin/config/diff.php?app= URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12094?
CVE-2019-12094 is a vulnerability in Horde Groupware Webmail Edition through 5.2.22 that allows XSS (cross-site scripting) attacks.
How severe is CVE-2019-12094?
CVE-2019-12094 has a severity rating of medium with a CVSS score of 6.1.
What is the affected software of CVE-2019-12094?
The affected software of CVE-2019-12094 is Horde Groupware Webmail Edition up to version 5.2.22.
How can I exploit CVE-2019-12094?
To exploit CVE-2019-12094, an attacker can use the admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI to perform a cross-site scripting attack.
Is there a fix for CVE-2019-12094?
Yes, you should update to a version of Horde Groupware Webmail Edition that is higher than 5.2.22 to fix CVE-2019-12094.