PT-2025-12433 · Horde+1 · Horde Imp+2

Published

2025-03-21

·

Updated

2025-05-23

·

CVE-2025-30349

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Horde IMP versions prior to 6.2.27 Horde Application Framework versions prior to 5.2.23
Description A Cross-Site Scripting (XSS) vulnerability was discovered in Horde IMP, allowing an attacker to hijack a user session by sending a crafted e-mail to an IMP user. The vulnerability can be exploited via a crafted text/html e-mail message with an onerror attribute, which may use base64-encoded JavaScript code. This issue has been exploited in the wild in March 2025.
Recommendations For Horde IMP versions prior to 6.2.27, upgrade to version 6.2.27-2+deb11u1 or later. For Horde Application Framework versions prior to 5.2.23, consider disabling the vulnerable component until a patch is available. As a temporary workaround, consider restricting access to the onerror attribute in e-mail messages to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-30349
DLA-4113-1

Affected Products

Debian
Horde Application Framework
Horde Imp