• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Resolved Horde XSS vulnerability in Open Document mime viewer

nethubonline

Regular Pleskian
Server operating system version
CentOS 7.6
Plesk version and microupdate number
18.0.45
Hi all,

There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.

Reference:
Horde PEAR server (Horde_Mime_Viewer 2.2.4)

Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
 
As far as I know, it was fixed since 18.0.43 version as PPP-56247 Vulnerability in Horde Mime Viewer (Linux)
 
Thanks IgorG, however I still find below code in 18.0.45

/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
PHP:
                    return array(
                        $this->_mimepart->getMimeId() => array(
                            'data' => str_replace(array_keys($tags), array_values($tags), $content),
                            'status' => array(),
                            'type' => 'text/html; charset=UTF-8'
                        )
                    );
 
The thing is that in file /usr/share/psa-horde/config/mime_drivers.php the processing of such attachments is disabled, as recommended in the first link in your original post.
 
Oh, thanks IgorG, I thought the fix will be using new Horde_Mime_Viewer version 2.2.4 .

Anyway the config already set to disable such attachments, we believe it is good now, thanks for clarify.
 
Back
Top