vendor:
Groupware Web mail Edition
by:
Marcela Benetrix
6,5
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Groupware Web mail Edition
Affected Version From: 5.1.2
Affected Version To: 5.1.2
Patch Exists: YES
Related CWE: CVE-2013-6275
CPE: horde:webmail_edition
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Multiple CSRF Horde Groupware Web mail Edition
Horde Groupware Webmail Edition is a free, enterprise ready, browser based communication suite. Several functionalities from Rules section were found to miss the token so as to prevent CSRF. A proof-of-concept code was provided to demonstrate the vulnerability. These were found at: Creating a rule, Updating, Enabling, Deleting.
Mitigation:
Vendor was notified and the issue was fixed in the next version 5.1.3