In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for Debian:unstable
php-horde
.
Note: Versions mentioned in the description apply only to the upstream php-horde
package and not the php-horde
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.