Filtered by vendor Horde
Subscriptions
Filtered by product Groupware
Subscriptions
Total
45 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-12095 | 1 Horde | 1 Groupware | 2024-11-21 | 8.8 High |
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload. | ||||
CVE-2019-12094 | 1 Horde | 1 Groupware | 2024-11-21 | 6.1 Medium |
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI. | ||||
CVE-2013-6365 | 3 Debian, Horde, Opensuse | 3 Debian Linux, Groupware, Opensuse | 2024-11-21 | 5.3 Medium |
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions | ||||
CVE-2013-6364 | 2 Debian, Horde | 2 Debian Linux, Groupware | 2024-11-21 | 8.8 High |
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book | ||||
CVE-2013-6275 | 2 Debian, Horde | 2 Debian Linux, Groupware | 2024-11-21 | 6.5 Medium |
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. |