#VU63922 Cross-site request forgery in Groupware Webmail Edition - CVE-2022-30287
Published: June 2, 2022
Groupware Webmail Edition
Horde Project
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. The vulnerability can be exploited by an user of a Horde instance or a remote attacker can trick a victim to open a specially crafted mail to execute arbitrary code on the underlying server.