• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Resolved Horde XSS vulnerability in Open Document mime viewer

nethubonline

Regular Pleskian
Server operating system version
CentOS 7.6
Plesk version and microupdate number
18.0.45
Hi all,

There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.

Reference:
Horde PEAR server (Horde_Mime_Viewer 2.2.4)

Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
 
As far as I know, it was fixed since 18.0.43 version as PPP-56247 Vulnerability in Horde Mime Viewer (Linux)
 
Thanks IgorG, however I still find below code in 18.0.45

/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
PHP:
                    return array(
                        $this->_mimepart->getMimeId() => array(
                            'data' => str_replace(array_keys($tags), array_values($tags), $content),
                            'status' => array(),
                            'type' => 'text/html; charset=UTF-8'
                        )
                    );
 
The thing is that in file /usr/share/psa-horde/config/mime_drivers.php the processing of such attachments is disabled, as recommended in the first link in your original post.
 
Oh, thanks IgorG, I thought the fix will be using new Horde_Mime_Viewer version 2.2.4 .

Anyway the config already set to disable such attachments, we believe it is good now, thanks for clarify.
 

Similar threads

Back
Top