lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
{ "binaries": [ { "binary_name": "php-horde-mime-viewer", "binary_version": "2.1.2-1build1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26874.json"
{ "binaries": [ { "binary_name": "php-horde-mime-viewer", "binary_version": "2.2.2-1" } ] }