Multiple Horde products contain a flaw related to the access control system, that may allow an attacker to perform a privilege escalation. No further details have been provided.
An upgrade is required as there are no known workarounds. Upgrade to Horde Groupware 1.0.3 or higher, as it has been reported to fix this vulnerability. Other products affected have got an available upgrade.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.