Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=updatef&username= or admin/user.php?form=removef&username= or admin/config/diff.php?app= URI.
{ "binaries": [ { "binary_name": "php-horde-core", "binary_version": "2.11.1-2ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "php-horde-core", "binary_version": "2.22.6+debian0-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "php-horde-trean", "binary_version": "1.1.4-1build1" } ] }
{ "binaries": [ { "binary_name": "php-horde-core", "binary_version": "2.31.1+debian0-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "php-horde-trean", "binary_version": "1.1.9-1" } ] }