PT-2025-48687 · Horde+1 · Horde Groupware+1

·

CVE-2025-41066

·

Published

2025-12-02

·

Updated

2025-12-02

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Horde Groupware version 5.2.22
Description An unauthenticated attacker can determine the existence of valid accounts on the system. This is achieved by sending an HTTP request to the ''/imp/attachment.php'' endpoint with the parameters id and u. If the specified user exists, the server returns the download of an empty file. If the user does not exist, no download is initiated, revealing whether the user is valid.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-41066

Affected Products

Debian
Horde Groupware