CVE-2019-12095: Horde Groupware
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.
Affected products
- Horde Groupware: up to and including 5.2.22
Published 2019-10-24. Last modified 2026-06-17.