• We value your experience with Plesk during 2024
    Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024.
    Please take this short survey:

    https://pt-research.typeform.com/to/AmZvSXkx
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Resolved Horde XSS vulnerability in Open Document mime viewer

nethubonline

Regular Pleskian
Server operating system version
CentOS 7.6
Plesk version and microupdate number
18.0.45
Hi all,

There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.

Reference:
Horde PEAR server (Horde_Mime_Viewer 2.2.4)

Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
 
As far as I know, it was fixed since 18.0.43 version as PPP-56247 Vulnerability in Horde Mime Viewer (Linux)
 
Thanks IgorG, however I still find below code in 18.0.45

/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
PHP:
                    return array(
                        $this->_mimepart->getMimeId() => array(
                            'data' => str_replace(array_keys($tags), array_values($tags), $content),
                            'status' => array(),
                            'type' => 'text/html; charset=UTF-8'
                        )
                    );
 
The thing is that in file /usr/share/psa-horde/config/mime_drivers.php the processing of such attachments is disabled, as recommended in the first link in your original post.
 
Oh, thanks IgorG, I thought the fix will be using new Horde_Mime_Viewer version 2.2.4 .

Anyway the config already set to disable such attachments, we believe it is good now, thanks for clarify.
 

Similar threads

Back
Top