Submitted by ep on
http://www.securityfocus.com/bid/43515/info
"Horde IMP Webmail is prone to an HTML-injection vulnerability because
it fails to sufficiently sanitize user-supplied data before it is used
in dynamic content.
Attacker-supplied HTML or JavaScript code could run in the context of
the affected site, potentially allowing the attacker to steal
cookie-based authentication credentials and to control how the site is
rendered to the user; other attacks are also possible.
Horde IMP 4.3.7 is affected; other versions may also be vulnerable."
Updates are available for download. It is recommended that Horde IMP
admins update their code to the latest available.
Thanks,
ep