CVE-2021-26929
PoC ×2—CVSS 3.1
6.1 medium
EPSS
5%p92
Published
()
Modified
Description
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \x00\x00\x00 and \x01\x01\x01 interferes with XSS defenses.
In the news0 stories
No ingested article mentions this CVE yet.