CVE-2021-26929

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of x00x00x00 and x01x01x01 interferes with XSS defenses.
Configurations

Configuration 1

cpe:2.3:a:horde:groupware:*:*:*:*:webmail:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Information

Published : 2021-02-14 04:15

Updated : 2021-04-19 08:21


NVD link : CVE-2021-26929

Mitre link : CVE-2021-26929

Products Affected
No products.
CWE