"Horde IMP Webmail is prone to an HTML-injection vulnerability because
it fails to sufficiently sanitize user-supplied data before it is used
in dynamic content.
the affected site, potentially allowing the attacker to steal
cookie-based authentication credentials and to control how the site is
rendered to the user; other attacks are also possible.
Horde IMP 4.3.7 is affected; other versions may also be vulnerable."
Updates are available for download. It is recommended that Horde IMP
admins update their code to the latest available.