Executive brief
Horde IMP is a popular webmail application used to access email accounts. A security flaw in its message composition feature allows an attacker with a valid account to steal sensitive files from the underlying server. By sending a specially crafted email, the attacker can force the server to include private system files as attachments in the outgoing message. This could also be triggered against legitimate users via a malicious link (CSRF).
Technical details
A path traversal vulnerability exists in the IMP_Compose::_convertToRelated() function within lib/Compose.php. The application uses stripos() to validate that image source URLs in HTML emails start with a specific CKEditor path prefix, but it fails to properly sanitize the remainder of the path. An attacker can append traversal sequences (e.g., ../) after the valid prefix to bypass the check. This causes file_get_contents() to read arbitrary files from the server, which are then attached as MIME parts to the outgoing email. While primarily requiring authentication, the flaw is also exploitable via Cross-Site Request Forgery (CSRF) against an active session. The issue is resolved in version 7.0.1 by implementing stricter prefix validation and realpath() containment checks.
Affected products
- Horde IMP < 7.0.1
Timeline
- 2026-07-01: disclosed
- 2026-07-01: patched: Fixed in version 7.0.1
- 2026-07-01: advisory