CVE-2025-30349 is a high-severity cross-site scripting (XSS) vulnerability affecting Horde IMP through version 6.2.27 and Horde Application Framework through 5.2.23. This flaw allows an attacker to achieve account takeover by sending a specially crafted HTML email containing an onerror attribute with base64-encoded JavaScript. The vulnerability has a CVSS score of 7.2, indicating a high risk due to its network attack vector and low attack complexity, potentially leading to partial confidentiality and integrity compromise. Notably, this vulnerability is being actively exploited in the wild as of March 2025, despite a lack of public exploit code or Metasploit/Nuclei modules, and has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 6.2.27CPE match | cpe:2.3:a:horde:imp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.