Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-26874

Опубликовано: 11 мар. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.5
CVSS3: 5.4

Описание

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
esm-apps/bionic

needs-triage

esm-apps/xenial

needed

trusty

ignored

end of standard support
upstream

released

2.2.4+debian0-1
xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 54%
0.0031
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

CVSS3: 5.4
debian
почти 4 года назад

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows ...

CVSS3: 5.4
github
почти 4 года назад

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

EPSS

Процентиль: 54%
0.0031
Низкий

3.5 Low

CVSS2

5.4 Medium

CVSS3