CVE-2025-30349
—Cross-Site Scripting in Horde IMP Webmail Enables Account Takeover
Horde IMP webmail through version 6.2.27, as used with Horde Application Framework through 5.2.23, contains a cross-site scripting flaw (CWE-79) in its handling of text/html email messages. An attacker triggers the flaw by sending a crafted HTML email whose onerror attribute executes attacker-controlled JavaScript — which may be base64-encoded — when the message is rendered. Successful exploitation leads to account takeover of the victim's webmail session, letting the attacker read mail, act as the user, and potentially pivot to other services sharing the credentials. Any installation running IMP up to and including 6.2.27 with Horde Application Framework up to and including 5.2.23 is affected. The flaw was exploited in the wild in March 2025, carries a high probability of near-term exploitation (EPSS 31.3%, 98th percentile), and is not yet listed in CISA KEV, with no public proof-of-concept known.
What to do: Upgrade Horde IMP to a release newer than 6.2.27 and Horde Application Framework to a release newer than 5.2.23 as soon as patched versions are published by the Horde project, prioritizing internet-facing webmail servers given the confirmed in-the-wild exploitation. Until patching, consider restricting or disabling rendering of text/html messages and inspect quarantine/mail logs for HTML messages using onerror handlers. Review webmail access and session logs for signs of account takeover and reset credentials for any suspected victims.
| Horde IMP | all versions through and including 6.2.27 |
| Horde Application Framework | all versions through and including 5.2.23 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.