nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-41066 CVE-2025-41066
MEDIUM
Disclosure of sensitive information in Horde Groupware
Record summary
CVE-2025-41066 has a selected CVSS score of 6.9 (medium).
Description
Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vulnerability, an HTTP request must be sent to ‘/imp/attachment.php’ including the parameters ‘id’ and ‘u’. If the specified user exists, the server will return the download of an empty file; if it does not exist, no download will be initiated, which unequivocally reveals the validity of the user.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GroupwareBrowse Horde / GroupwareDefault status: unaffected | CVE List | 5.2.22 | affected |
References
2incibe.es
https://www.incibe.es/en/incibe-cert/notices/aviso/disclosure-sensitive-information-horde-groupware