CVE-2013-5035: Htmlcleaner Project Htmlcleaner
Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
Affected products
- Htmlcleaner Project Htmlcleaner: up to and including 2.5; version 0.8 only; version 0.9 only; version 1.0 only; version 1.0.5 only; version 1.1 only; …
- Open-Xchange Open-Xchange Appsuite: version 7.2.2 only
Published 2013-09-05. Last modified 2026-06-16.