Horde Webmail 5.2.22 - Account Takeover via Email
Blog post from Sonar
The Horde webmail suite is a popular, browser-based communication solution that can be vulnerable to certain security threats. The article discusses an unusual cross-site scripting (XSS) vulnerability in the Horde webmailer that allows an attacker to craft a malicious OpenOffice document that, when previewed as an email attachment, enables the attacker to steal all emails from the victim's account. This vulnerability was reported almost six months ago, but there is currently no official patch available. To mitigate this vulnerability, administrators can disable the rendering of OpenOffice attachments by editing the Horde installation's configuration file. The article emphasizes the importance of sanitizing HTML documents after XSLT rendering, especially when using third-party libraries or stylesheets.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.