Security Advisory

CVE-2019-12095

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-10-24 17:09:59
Last updated 2024-08-04 23:10:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.