http://www.securityfocus.com/bid/28898
Horde Webmail is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
I hope we see a hotfix for this soon, as a security bug is very important.
Horde Webmail is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials.
I hope we see a hotfix for this soon, as a security bug is very important.