nethubonline
Regular Pleskian
- Server operating system version
- CentOS 7.6
- Plesk version and microupdate number
- 18.0.45
Hi all,
There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.
Reference:
Horde PEAR server (Horde_Mime_Viewer 2.2.4)
Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.
Reference:
Horde Webmail 5.2.22 - Account Takeover via Email
We recently discovered a code vulnerability in Horde Webmail that can be used by attackers to take over email accounts by sending a malicious email.
blog.sonarsource.com
[jan] Fix XSS vulnerability in Open Document mime viewer with differe… · horde/Mime_Viewer@02b46ce
…nt code path (Reported by: Mahdi Pasche <[email protected]>).
github.com
Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php