lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3045-1 | php-horde-mime-viewer security update |
Debian DLA |
DLA-3089-1 | php-horde-mime-viewer security update |
Debian DLA |
DLA-3924-1 | php-horde-mime-viewer security update |
EUVD |
EUVD-2022-31423 | lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-19T18:02:57.612Z
Reserved: 2022-03-11T00:00:00.000Z
Link: CVE-2022-26874
No data.
Status : Modified
Published: 2022-03-11T07:15:08.037
Modified: 2024-11-21T06:54:43.603
Link: CVE-2022-26874
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD