• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
9 year old unpatched email hacking bug uncovered in horde webmail software

9-Year-Old Unpatched Email Hacking Bug Uncovered in Horde Webmail Software

You are here: Home / General Cyber Security News / 9-Year-Old Unpatched Email Hacking Bug Uncovered in Horde Webmail Software
February 23, 2022

Buyers of Horde Webmail are being urged to disable a aspect to contain a 9-yr-aged unpatched security vulnerability in the software package that could be abused to gain finish obtain to email accounts simply by previewing an attachment.

“This presents the attacker obtain to all delicate and maybe solution information and facts a target has saved in their email account and could let them to gain further more accessibility to the inside solutions of an group,” SonarSource vulnerability researcher, Simon Scannell, stated in a report.

An “all volunteer project,” the Horde Challenge is a cost-free, browser-centered conversation suite that allows consumers to browse, mail, and organize email messages as very well as handle and share calendars, contacts, responsibilities, notes, information, and bookmarks.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper take secure and enxrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized seller: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Automatic GitHub Backups

The flaw, which was introduced as part of a code improve pushed on November 30, 2012, relates to a circumstance of an “strange” stored cross-website scripting flaw (aka persistent XSS) that enables an adversary to craft an OpenOffice document in this sort of a method that when it is previewed, it mechanically executes arbitrary JavaScript payload.

Saved XSS attacks come up when a destructive script is injected specifically into a susceptible web application’s server, these kinds of as a comment industry of a internet site, resulting in the untrusted code to be retrieved and transmitted to the victim’s browser each individual time the stored information is requested.

“The vulnerability triggers when a qualified person sights an attached OpenOffice document in the browser,” Scannell explained. “As a result, an attacker can steal all emails the target has sent and been given.”

Even worse, must an administrator account with a personalised, malicious email is correctly compromised, the attacker could abuse this privileged entry to take around the entire webmail server.

Prevent Data Breaches

The shortcoming was initially noted to the job maintainers on August 26, 2021, but to day no fixes have been transported even with confirmation from the vendor acknowledging the flaw. We have achieved out to Horde for more remark, and we will update if we listen to again.

In the interim, Horde Webmail buyers are suggested to disable the rendering of OpenOffice attachments by editing the config/mime_drivers.php file to add the ‘disable’ => true configuration choice to OpenOffice mime handler.

Observed this posting attention-grabbing? Follow THN on Facebook, Twitter  and LinkedIn to read a lot more exceptional articles we put up.


Some pieces of this write-up are sourced from:
thehackernews.com

Previous Post: «25 malicious javascript libraries distributed via official npm package repository 25 Malicious JavaScript Libraries Distributed via Official NPM Package Repository
Next Post: Chinese Experts Uncover Details of Equation Group’s Bvp47 Covert Hacking Tool chinese experts uncover details of equation group's bvp47 covert hacking»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Sioux Falls Funds DSU Cybersecurity Lab
  • ‘CryptoRom’ Crypto-Scam is Back via Side-Loaded Apps
  • Irish Watchdog Fines Meta $19m Over Data Breach
  • Avast Merger Raises Competition Concerns
  • Linux botnet spreads using Log4Shell flaw
  • Another Destructive Wiper Targets Organizations in Ukraine
  • New “B1txor20” Linux Botnet Uses DNS Tunnel and Exploits Log4J Flaw
  • New Infinite Loop Bug in OpenSSL Could Let Attackers Crash Remote Servers
  • FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug
  • Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

Copyright © TheCyberSecurity.News, All Rights Reserved.