PT-2022-18118 · Apache+1 · Openoffice+2

Mahdi Pasche

·

Published

2022-03-11

·

Updated

2024-10-19

·

CVE-2022-26874

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Horde Mime Viewer versions prior to 2.2.4
Description The issue allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
Recommendations For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider disabling the rendering of OpenOffice documents in lib/Horde/Mime/Viewer/Ooo.php until a patch is available. Restrict access to the lib/Horde/Mime/Viewer/Ooo.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-26874
DLA-3045-1
DLA-3089-1
DLA-3924-1

Affected Products

Horde Groupware Webmail Edition
Horde Mime Viewer
Openoffice