CVE-2022-26874: XSS
Published Mar 11, 2022
·Updated
lib/Horde/Mime/Viewer/Ooo.php in Horde MimeViewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
Affected Software
3 affected components
Horde Horde Mime Viewer<2.2.4
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Mar 11, 2022
CVE Published
via MITRE·06:02 AM
Data Sourced
via MITRE·06:02 AM
Description
Frequently Asked Questions
1
What is CVE-2022-26874?
CVE-2022-26874 is a vulnerability in the Horde Mime_Viewer library that allows XSS attacks via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition.
2
How does CVE-2022-26874 affect Horde Mime_Viewer?
CVE-2022-26874 affects Horde Mime_Viewer versions before 2.2.4, allowing XSS attacks through OpenOffice documents.
3
What is the severity of CVE-2022-26874?
The severity of CVE-2022-26874 is medium, with a severity score of 5.4.
4
How can I fix CVE-2022-26874?
To fix CVE-2022-26874, upgrade to Horde Mime_Viewer version 2.2.4 or above.
5
Are there any references for CVE-2022-26874?
Yes, you can find references for CVE-2022-26874 at the following links: [link1], [link2], [link3].