debian · CVE-2019-12095

Quick triage

Priority: unimportant Published: Updated: Sun, 19 Jul 2026 12:01:35 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-12095 unimportant priority: Debian including 2 source packages (php-horde, php-horde-trean), 6 status rows across 3 suites (bookworm, bullseye, sid): open 3, resolved 3.

Description:

Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.

cvelogic Threat Intelligence