Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mchq-vv84-m9gr

Опубликовано: 21 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

EPSS

Процентиль: 95%
0.18609
Средний

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
ubuntu
11 месяцев назад

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

CVSS3: 7.2
nvd
11 месяцев назад

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

CVSS3: 7.2
debian
11 месяцев назад

Horde IMP through 6.2.27, as used with Horde Application Framework thr ...

EPSS

Процентиль: 95%
0.18609
Средний

7.2 High

CVSS3

Дефекты

CWE-79