Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.0.13"
}
],
"source": "CPE_RANGE",
"vendor_product": "horde:gollem",
"cpes": [
"cpe:2.3:a:horde:gollem:*:*:*:*:*:*:*:*"
]
}
]
}