We would like to bring your attention to the following 0-day exploit we have recently become aware of.
The Horde Webmail Software has been found to contain a nine year old unpatched security vulnerability. Exploitation of this vulnerability could be used to gain complete access to email accounts simply by previewing an attachment.
Affected Version
5.2.22
The flaw, believed to have been introduced by a code change in November 2012, relates to a stored cross-site scripting flaw (persistent XSS) that allows an attacker to craft an OpenOffice document in such a manner that when it is previewed, it automatically executes an arbitrary JavaScript payload.
The vulnerability triggers when a targeted user views an attached OpenOffice document in the browser. This results in the ability for an attacker to steal all emails the victim has sent and received. If an attacker was successful in targeting an administrator by sending a personalised, malicious email, they could abuse this privileged access to take over the entire webmail server.
Remediation
At this time, there are no patches for Horde webmail that are available, however Horde Webmail users are advised to disable the rendering of OpenOffice attachments by editing the config/mime_drivers.php file to add the ‘disable’ => true configuration option to OpenOffice mime handler.
We are actively monitoring the situation.
References:
-
SonarSource: https://blog.sonarsource.com/horde-webmail-account-takeover-via-email
-
The Hacker News: https://thehackernews.com/2022/02/9-year-old-unpatched-email-hacking-bug.html
Swarm Intelligence: LiteLLM was the end of the chain, not the beginning.
LiteLLM’s PyPI package was backdoored for under an hour on March 24. SSH keys, cloud credentials, and CI/CD secrets exfiltrated at install. Here is what is…
Handala & MuddyWater: MDM Weaponization at Enterprise Scale
On 11 March 2026, an Iranian two-team operation destroyed 200,000 enterprise devices at Stryker without deploying a single piece of malware. One compromised Global Administrator account.…
Why Robbing Banks Is Easy (And Why That Should Terrify You)
A globally recognized ethical hacker shares real social engineering stories from legally robbing banks across five continents. The tools change. The human vulnerabilities don’t.