THREAT OPS › Threat News › FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)
FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)
<p>Posted by Evan Tang on Aug 26</p><a href="https://blog.evan.lat/posts/CVE-2026-65053/" rel="nofollow">https://blog.evan.lat/posts/CVE-2026-65053/</a><br /> <br /> the blog talks about two vulns that are chainable together. for the sake of<br /> brevity ill write up on the stored xss one.<br /> <br /> in lib/Mime/Status.php, we see a pretty viable xss sink:<br /> <br /> $out .= '<tr>&
Indicators of compromise
- CVE-2026-65053cve
- https://blog.evan.lat/posts/CVE-2026-65053/url
Original source: https://seclists.org/fulldisclosure/2026/Aug/115