{"id":"UBUNTU-CVE-2021-26929","details":"An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled by preProcess in Text2html.php, because bespoke use of \\x00\\x00\\x00 and \\x01\\x01\\x01 interferes with XSS defenses.","modified":"2025-10-24T04:50:10Z","published":"2021-02-14T04:15:00Z","upstream":["CVE-2021-26929"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-26929"},{"type":"REPORT","url":"https://lists.horde.org/archives/announce/2021/001298.html"},{"type":"REPORT","url":"https://github.com/horde/Text_Filter/commit/c26f938854c36b981558a3b1b9b2f81403cff60e"},{"type":"REPORT","url":"https://github.com/horde/Text_Filter/commit/a2f67da064d7a91440b7a2448e56a6387ab94c67"},{"type":"REPORT","url":"https://www.alexbirnberg.com/horde-xss.html"},{"type":"REPORT","url":"https://github.com/horde/webmail/releases"},{"type":"REPORT","url":"https://www.horde.org/apps/webmail"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-26929"}],"affected":[{"package":{"name":"php-horde-text-filter","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/php-horde-text-filter@2.3.3-1ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2-1","2.3.2-2","2.3.3-1","2.3.3-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-horde-text-filter","binary_version":"2.3.3-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-26929.json"}},{"package":{"name":"php-horde-text-filter","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/php-horde-text-filter@2.3.5-1ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.5-1","2.3.5-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-horde-text-filter","binary_version":"2.3.5-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-26929.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}