{"id":"CVE-2025-30349","details":"Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that may use base64-encoded JavaScript code), as exploited in the wild in March 2025.","modified":"2026-08-12T03:51:09.357917667Z","published":"2025-03-21T00:00:00Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30349.json"},"references":[{"type":"WEB","url":"https://github.com/horde/base/releases/tag/v5.2.23"},{"type":"WEB","url":"https://github.com/horde/imp/blob/fd9212ca3b72ff834504af4886f7d95138619bd4/doc/INSTALL.rst?plain=1#L23-L25"},{"type":"WEB","url":"https://github.com/horde/imp/blob/fd9212ca3b72ff834504af4886f7d95138619bd4/doc/INSTALL.rst?plain=1#L61-L62"},{"type":"WEB","url":"https://github.com/horde/imp/releases/tag/v6.2.27"},{"type":"WEB","url":"https://github.com/horde/webmail/releases/tag/v5.2.22"},{"type":"WEB","url":"https://github.com/natasaka/CVE-2025-30349/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00008.html"},{"type":"WEB","url":"https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057781.html"},{"type":"WEB","url":"https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057784.html"},{"type":"WEB","url":"https://web.archive.org/web/20250321152616/https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057781.html"},{"type":"WEB","url":"https://web.archive.org/web/20250321162434/https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057784.html"},{"type":"WEB","url":"https://www.horde.org/apps/horde"},{"type":"WEB","url":"https://www.horde.org/apps/imp"},{"type":"WEB","url":"https://www.horde.org/download/horde"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30349.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30349"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/horde/base","events":[{"introduced":"0"},{"fixed":"ca32251e62b2ed91594da81ca2e5d34b85a03d03"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.2.23"}],"source":["DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/horde/imp","events":[{"introduced":"0"},{"fixed":"d8415bd1e8c0d07302e974294522c28af280ba2a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.2.27"},{"fixed":"6.2.27"}],"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/horde/webmail","events":[{"introduced":"0"},{"fixed":"9443d11b0d68ee718b59c27fbe360e4a0ae95c60"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v5.2.21","v5.2.20","v5.2.19","v5.2.18","v5.2.17","v5.2.16","v5.2.15","v5.2.14","v5.2.13","v5.2.12","v5.2.11","v5.2.10","v5.2.9","v5.2.8","v5.2.7","v5.2.6","v5.2.5","v5.2.4","v5.2.3","v5.2.2","v5.2.1","v5.2.0","v5.2.0rc2","v5.2.0rc1","v5.2.0beta2","v5.2.0beta1","v5.2.0alpha1","v5.1.5","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.1.0rc1","v5.1.0beta3","v5.1.0beta2","v5.1.0beta1","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v5.0.0rc1","v5.0.0beta6","v5.0.0beta5","v5.0.0beta4","v5.0.0beta3","v5.0.0beta2","v5.0.0beta1","v5.0.0alpha1","v4.0.1","v4.0.0","v4.0.0rc2","v4.0.0rc1","v4.0.0beta1","v6.2.26","v6.2.25","v6.2.24","v6.2.23","v6.2.22","v6.2.21","v6.2.20","v6.2.19","v6.2.18","v6.2.17","v6.2.16","v6.2.15","v6.2.14","v6.2.13","v6.2.12","v6.2.11","v6.2.10","v6.2.9","v6.2.8","v6.2.7","v6.2.6","v6.2.5","v6.2.4","v6.2.3","v6.2.2","v6.2.1","v6.2.0","v6.2.0rc1","v6.2.0beta3","v6.2.0beta2","v6.2.0beta1","v6.2.0alpha1","v6.1.6","v6.1.5","v6.1.4","v6.1.3","v6.1.2","v6.1.1","v6.1.0","v6.1.0rc1","v6.1.0beta2","v6.1.0beta1","v6.0.4","v6.0.3","v6.0.2","v6.0.1","v6.0.0","v6.0.0rc2","v6.0.0rc1","v6.0.0beta4","v6.0.0beta3","v5.0.22","v5.0.21","v5.0.20","v5.0.19","v5.0.18","v5.0.17","v5.0.16","v5.0.15","v5.0.14","v5.0.13","v5.0.12","v5.0.11","v5.0.10","v5.0.9","v5.0.8","v5.0.7","v5.0.6","v5.0.5","v5.0.0rc2","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30349.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}