CVE-2022-26874
PoC —CVSS 3.1
5.4 medium
EPSS
1%p62
Published
()
Modified
Description
lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
In the news0 stories
No ingested article mentions this CVE yet.