CVE-2019-12095

HIGH

Horde Groupware < 5.2.22 - Cross-Site Request Forgery via treanBookmarkTags Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-12095. PoCs published by InfinitumIT.

AI-analyzed exploit summary This PoC demonstrates a combination of CSRF and XSS vulnerabilities in Horde Webmail to steal emails, execute remote commands, and perform SQL injection. It includes client-side JavaScript for exploitation and server-side PHP for data exfiltration.

Description

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

Exploits (1)

exploitdb WORKING POC
by InfinitumIT · textwebappsphp
https://www.exploit-db.com/exploits/46903

This PoC demonstrates a combination of CSRF and XSS vulnerabilities in Horde Webmail to steal emails, execute remote commands, and perform SQL injection. It includes client-side JavaScript for exploitation and server-side PHP for data exfiltration.

Classification
Working Poc 95%
Attack Type
Xss, Csrf, Sqli, Rce
Complexity
Moderate
Reliability
Reliable
Target: Horde Webmail <= v5.2.22
Auth required
Prerequisites: Victim interaction (clicking a link) · Attacker-controlled server to host malicious scripts · Valid session or authentication tokens for CSRF
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory x_refsource_misc
https://numanozdemir.com/respdisc/horde/horde.mp4
Exploit, Third Party Advisory x_refsource_misc
https://numanozdemir.com/respdisc/horde/horde.txt
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/46903
Exploit, Third Party Advisory x_refsource_misc
https://cxsecurity.com/issue/WLB-2019050199
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/161333
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://bugs.horde.org/ticket/14926
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/12/msg00015.html

Scores

CVSS v3 8.8
EPSS 0.0112
EPSS Percentile 61.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352 CWE-79
Status published
Products (1)
horde/groupware < 5.2.22
Published Oct 24, 2019
Tracked Since Feb 18, 2026