CVE-2019-12094
24.10.2019, 17:15
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.
| Vendor | Product | Version |
|---|---|---|
| horde | groupware | 𝑥 ≤ 5.2.22 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| php-horde-core |
| ||||||||||||||||||||||||||||
| php-horde-trean |
|
References