ZeroHour

CVE-2025-30349

Cross-Site Scripting in Horde IMP Webmail Enables Account Takeover

CVSS 3.1
7.2 high
EPSS
31%p98
Published
()
Modified
AI analysis

Horde IMP webmail through version 6.2.27, as used with Horde Application Framework through 5.2.23, contains a cross-site scripting flaw (CWE-79) in its handling of text/html email messages. An attacker triggers the flaw by sending a crafted HTML email whose onerror attribute executes attacker-controlled JavaScript — which may be base64-encoded — when the message is rendered. Successful exploitation leads to account takeover of the victim's webmail session, letting the attacker read mail, act as the user, and potentially pivot to other services sharing the credentials. Any installation running IMP up to and including 6.2.27 with Horde Application Framework up to and including 5.2.23 is affected. The flaw was exploited in the wild in March 2025, carries a high probability of near-term exploitation (EPSS 31.3%, 98th percentile), and is not yet listed in CISA KEV, with no public proof-of-concept known.

What to do: Upgrade Horde IMP to a release newer than 6.2.27 and Horde Application Framework to a release newer than 5.2.23 as soon as patched versions are published by the Horde project, prioritizing internet-facing webmail servers given the confirmed in-the-wild exploitation. Until patching, consider restricting or disabling rendering of text/html messages and inspect quarantine/mail logs for HTML messages using onerror handlers. Review webmail access and session logs for signs of account takeover and reset credentials for any suspected victims.

Affected
Horde IMPall versions through and including 6.2.27
Horde Application Frameworkall versions through and including 5.2.23
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.