Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=updatef&username= or admin/user.php?form=removef&username= or admin/config/diff.php?app= URI.
{ "binaries": [ { "binary_version": "2.11.1-2ubuntu0.1~esm1", "binary_name": "php-horde-core" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12094.json"
{ "binaries": [ { "binary_version": "2.22.6+debian0-1ubuntu1", "binary_name": "php-horde-core" } ] }
{ "binaries": [ { "binary_version": "1.1.4-1build1", "binary_name": "php-horde-trean" } ] }
{ "binaries": [ { "binary_version": "2.31.1+debian0-1ubuntu1", "binary_name": "php-horde-core" } ] }
{ "binaries": [ { "binary_version": "1.1.9-1", "binary_name": "php-horde-trean" } ] }