CVE-2025-30349: XSS
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30349?
CVE-2025-30349 is considered a high severity vulnerability due to its potential for account takeover through XSS attacks.
How do I fix CVE-2025-30349?
To remediate CVE-2025-30349, update to Horde IMP version 6.2.28 or later and Horde Application Framework version 5.2.24 or later.
What is the impact of CVE-2025-30349?
CVE-2025-30349 allows attackers to execute malicious scripts via crafted HTML emails, potentially leading to unauthorized access to user accounts.
Which versions are affected by CVE-2025-30349?
CVE-2025-30349 affects Horde IMP versions up to and including 6.2.27 and Horde Application Framework versions up to and including 5.2.23.
When was CVE-2025-30349 first exploited?
CVE-2025-30349 was reported to be exploited in the wild in March 2025.