Security Advisory

CVE-2022-26874

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-03-11 06:02:56
Last updated 2024-10-19 18:02:57
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.