Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Horde Webmail - Remote Code Execution via Email

Blog post from Sonar

Post Details
Company
Date Published
Author
Simon Scannell
Word Count
1,278
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Horde webmail application has a vulnerability that allows an attacker to fully take over an instance as soon as a victim opens an email the attacker sent, without requiring further interaction from the user. The vulnerability exists in the default configuration and can be exploited with no knowledge of a targeted Horde instance. An authenticated user can execute arbitrary code on the underlying server by sending a maliciously crafted email that triggers the vulnerability via Cross-Site-Request-Forgery (CSRF). This allows an attacker to intercept every sent and received email, access password-reset links, and steal all credentials of users logging into the webmail service. The vendor has not released a patch at the time of writing, making it crucial for organizations using Horde webmail to consider alternative solutions.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.