|
Horde Groupware 1.2.6 and Horde Groupware Webmail Edition 1.2.6 contains a flaw that allows a remote Cross-site Request Forgery (CSRF / XSRF) attack. The applications allow users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. change certain settings by tricking a logged-in user into visiting a specially crafted website. The vulnerability is confirmed in Horde Groupware 1.2.6 and Horde Groupware Webmail Edition 1.2.6. Other versions may also be affected.
|