Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
BID:40542
Info
Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 40542 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2010 12:00AM |
| Updated: | May 14 2010 12:00AM |
| Credit: | Russ McRee |
| Vulnerable: |
Horde Project Groupware Webmail Edition 1.2.6 Horde Project Groupware 1.2.6 |
| Not Vulnerable: | |
Discussion
Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
Horde Groupware is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible.
Horde Groupware 1.2.6 and Horde Groupware Webmail Edition 1.2.6 are vulnerable.
Horde Groupware is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible.
Horde Groupware 1.2.6 and Horde Groupware Webmail Edition 1.2.6 are vulnerable.
Exploit / POC
Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice a user into visiting a malicious site.
To exploit this issue, an attacker must entice a user into visiting a malicious site.
Solution / Fix
Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Horde Groupware Unspecified Cross Site Request Forgery Vulnerability
References:
References:
- Groupware Homepage (Horde Project)
- HIO-2010-0514 Horde Web Mail CSRF Vulnerability (HolisticInfoSec.org)