THREATOPS
THREAT OPSThreat News › FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)

FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)

medfulldisclosurePublished 2026-08-26

<p>Posted by Evan Tang on Aug 26</p><a href="https://blog.evan.lat/posts/CVE-2026-65053/" rel="nofollow">https://blog.evan.lat/posts/CVE-2026-65053/</a><br /> <br /> the blog talks about two vulns that are chainable together. for the sake of<br /> brevity ill write up on the stored xss one.<br /> <br /> in lib/Mime/Status.php, we see a pretty viable xss sink:<br /> <br /> $out .= &apos;&lt;tr&gt;&

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Aug/115