CVE-2019-12094: Horde Groupware
Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.
Affected products
- Horde Groupware: up to and including 5.2.22
Published 2019-10-24. Last modified 2026-06-17.