[announce] [SECURITY] Horde 5.2.23 (final)

Michael J Rubinsky mrubinsk at horde.org
Sun Jun 14 20:42:38 UTC 2020


The Horde Team is pleased to announce the final release of the Horde
Application Framework version 5.2.23.

The Horde Application Framework is a flexible, modular, general-purpose web
application framework written in PHP. It provides an extensive array of
components that are targeted at the common problems and tasks involved in
developing modern web applications. It is the basis for a large number of
production-level web applications, notably the Horde Groupware suites.  
For more
information on Horde or the Horde Groupware suites, visit  
http://www.horde.org.

For upgrading instructions, please see
http://www.horde.org/apps/horde/docs/UPGRADING

For detailed installation and configuration instructions, please see
http://www.horde.org/apps/horde/docs/INSTALL

Thanks to Sulistyo Hidayat for reporting the vulnerability.

The major changes compared to the Horde version 5.2.21 are:
     * Fixed javascript injection vulnerability on the mobile login page.
     * Small bug fixes and improvements.

The full list of changes can be viewed here:

https://github.com/horde/base/blob/ca32251e62b2ed91594da81ca2e5d34b85a03d03/docs/CHANGES

Have fun!

The Horde Team.


More information about the announce mailing list