Vulnerability Description
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Horde | Groupware | <= 5.2.22 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/162187/Webmail-Edition-5.2.22-XSS-Remote-CoExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162194/Horde-Groupware-Webmail-5.2.22-CrossThird Party Advisory
- https://github.com/horde/webmail/releasesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00028.htmlMailing ListThird Party Advisory
- https://lists.horde.org/archives/announce/2021/001298.htmlMailing ListVendor Advisory
- https://www.alexbirnberg.com/horde-xss.htmlExploitThird Party Advisory
- https://www.horde.org/apps/webmailVendor Advisory
- http://packetstormsecurity.com/files/162187/Webmail-Edition-5.2.22-XSS-Remote-CoExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162194/Horde-Groupware-Webmail-5.2.22-CrossThird Party Advisory
- https://github.com/horde/webmail/releasesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00028.htmlMailing ListThird Party Advisory
- https://lists.horde.org/archives/announce/2021/001298.htmlMailing ListVendor Advisory
- https://www.alexbirnberg.com/horde-xss.htmlExploitThird Party Advisory
- https://www.horde.org/apps/webmailVendor Advisory
FAQ
What is CVE-2021-26929?
CVE-2021-26929 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaSc...
How severe is CVE-2021-26929?
CVE-2021-26929 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26929?
Check the references section above for vendor advisories and patch information. Affected products include: Horde Groupware, Debian Debian Linux.