Collected research
Horde Webmail 5.2.22 Account Takeover via Email
Shows stored XSS in Horde Webmail's OpenOffice attachment preview. An attacker-supplied XML document reaches a wildcard XSLT template that reconstructs arbitrary MathML-namespaced element names, including script; Horde returns the transformed XHTML without post-transform sanitization, enabling account takeover when the attachment is previewed.
Record
- Researcher
- Simon Scannell
- Published by
- Sonar
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Simon Scannell, first published at the original source. Preserved copies are kept so the citation survives its host.