CVE-2019-12094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
24/10/2019
Last modified:
03/12/2019

Description

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:horde:groupware:*:*:*:*:webmail:*:*:* 5.2.22 (including)