• Hi, Pleskians! We are running a UX testing of our upcoming product intended for server management and monitoring.
    We would like to invite you to have a call with us and have some fun checking our prototype. The agenda is pretty simple - we bring new design and some scenarios that you need to walk through and succeed. We will be watching and taking insights for further development of the design.
    If you would like to participate, please use this link to book a meeting. We will sent the link to the clickable prototype at the meeting.
  • Our UX team believes in the in the power of direct feedback and would like to invite you to participate in interviews, tests, and surveys.
    To stay in the loop and never miss an opportunity to share your thoughts, please subscribe to our UX research program. If you were previously part of the Plesk UX research program, please re-subscribe to continue receiving our invitations.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Resolved Horde XSS vulnerability in Open Document mime viewer

nethubonline

Regular Pleskian
Server operating system version
CentOS 7.6
Plesk version and microupdate number
18.0.45
Hi all,

There was a Horde XSS vulnerability in Open Document mime viewer, it has been fixed by Horde team 5 months ago, however Plesk does not update the Horde yet, the XSS vulnerability still exists in the most updated Plesk version. Please have developer update it to avoid attacker to gain full access to the email account in the Plesk server.

Reference:
Horde PEAR server (Horde_Mime_Viewer 2.2.4)

Related file:
/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
 
As far as I know, it was fixed since 18.0.43 version as PPP-56247 Vulnerability in Horde Mime Viewer (Linux)
 
Thanks IgorG, however I still find below code in 18.0.45

/usr/share/psa-pear/pear/php/Horde/Mime/Viewer/Ooo.php
PHP:
                    return array(
                        $this->_mimepart->getMimeId() => array(
                            'data' => str_replace(array_keys($tags), array_values($tags), $content),
                            'status' => array(),
                            'type' => 'text/html; charset=UTF-8'
                        )
                    );
 
The thing is that in file /usr/share/psa-horde/config/mime_drivers.php the processing of such attachments is disabled, as recommended in the first link in your original post.
 
Oh, thanks IgorG, I thought the fix will be using new Horde_Mime_Viewer version 2.2.4 .

Anyway the config already set to disable such attachments, we believe it is good now, thanks for clarify.
 
Back
Top