{"id":"CVE-2025-41066","summary":"Disclosure of sensitive information in Horde Groupware","details":"Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vulnerability, an HTTP request must be sent to ‘/imp/attachment.php’ including the parameters ‘id’ and ‘u’. If the specified user exists, the server will return the download of an empty file; if it does not exist, no download will be initiated, which unequivocally reveals the validity of the user.","modified":"2026-08-12T03:51:38.132212437Z","published":"2025-12-02T14:01:34.192Z","database_specific":{"cna_assigner":"INCIBE","cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41066.json","unresolved_ranges":[{"extracted_events":[{"introduced":"5.2.22"},{"last_affected":"5.2.22"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://www.incibe.es/en/incibe-cert/notices/aviso/disclosure-sensitive-information-horde-groupware"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41066.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-41066"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/horde/groupware","events":[{"introduced":"cf488bd4e87e1ff0d9e11a5a3c2d2f805172dd70"},{"last_affected":"cf488bd4e87e1ff0d9e11a5a3c2d2f805172dd70"}],"database_specific":{"cpe":"cpe:2.3:a:horde:groupware:5.2.22:*:*:*:-:*:*:*","extracted_events":[{"introduced":"5.2.22"},{"last_affected":"5.2.22"}],"source":"CPE_STRING"}}],"versions":["5.2.22","v5.2.22"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-41066.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/horde/horde","events":[{"introduced":"da4d701808c3af4100bd1f2d7f0fd07854267fa9"},{"last_affected":"da4d701808c3af4100bd1f2d7f0fd07854267fa9"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:horde:groupware:5.2.22:*:*:*:-:*:*:*","extracted_events":[{"introduced":"5.2.22"},{"last_affected":"5.2.22"}]}}],"versions":["5.2.22","webmail-5.2.22"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-41066.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}