CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-12095

HIGH
8.8
CVSS Severity Score
EPSS Score0.1500%
EPSS Percentile30.34th
Published2019年10月24日
Last Modified2024年11月21日

Vulnerability Description

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

Affected Platforms (CPE)

📦
Horde

Groupware

<= 5.2.22

References & Advisories

関連する脆弱性情報