3.5
CVSSv2

CVE-2022-26874

Published: 11/03/2022 Updated: 14/10/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer prior to 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

horde horde mime viewer

debian debian linux 9.0

debian debian linux 10.0