[fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln
Posted by ㅤevan via Fulldisclosure on Jul 02this is my first time sending to a mailing list so ive chosen
something easy. here goes: Summary: Horde Groupware’s IMP Webmail solution contains a path
traversal/local file inclusion vulnerability which could be exploited
to escalate privileges or bypass authentication (through CSRF if
unauthenticated). the vulnerability is in here: } elseif (strcasecmp($node->tagName, 'IMG') === 0) {
/* Check for smileys. They...